2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-38504MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix pp destruction warnings With mu...
CVE-2025-38503MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix assertion when building free space tree ...
CVE-2025-38502HIGH7.1In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial...
CVE-2025-8719MEDIUM6.4The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘base_...
CVE-2025-8464MEDIUM5.3The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in a...
CVE-2025-7499MEDIUM5.3The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia...
CVE-2025-8898CRITICAL9.8The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account ...
CVE-2025-8896MEDIUM6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2025-8089MEDIUM5.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in ...
CVE-2025-8113MEDIUM6.1The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting i...
CVE-2025-38501HIGH7.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with...
CVE-2025-8293MEDIUM6.4The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in...
CVE-2025-7686MEDIUM6.1The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2025-7684MEDIUM6.1The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-7683MEDIUM6.1The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-7668MEDIUM6.1The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2025-7664HIGH7.5The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_act...
CVE-2025-7651MEDIUM6.4The Earnware Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ew_hasrole' sho...
CVE-2025-7649MEDIUM6.4The Surbma | Recent Comments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2025-7441CRITICAL9.8The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42...
CVE-2025-7440MEDIUM6.4The Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $item['button_link']...
CVE-2025-7439MEDIUM6.4Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $anber_item['button_link...
CVE-2025-6221MEDIUM6.4The Embed Bokun plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versi...
CVE-2025-6080HIGH8.8The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in...
CVE-2025-6079HIGH8.8The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now