2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9010CRITICAL9.8A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability i...
CVE-2025-9009CRITICAL9.8A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown func...
CVE-2025-31961MEDIUM4.6HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai...
CVE-2025-9008CRITICAL9.8A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unk...
CVE-2025-9007HIGH8.8A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the fil...
CVE-2025-9006HIGH8.8A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of ...
CVE-2025-9005LOW3.7A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The ma...
CVE-2025-9004CRITICAL9.1A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/p...
CVE-2025-9003MEDIUM5.4A vulnerability has been found in D-Link DIR-818LW 1.04. This vulnerability affects unknown code of the file /bsc_lan.ph...
CVE-2025-9002CRITICAL9.8A vulnerability was identified in Surbowl dormitory-management-php 1.0. This affects an unknown part of the file login.p...
CVE-2025-9001HIGH7.5A vulnerability was determined in LemonOS up to nightly-2024-07-12 on LemonOS. Affected by this issue is the function HT...
CVE-2025-8867MEDIUM6.4The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multipl...
CVE-2025-8680MEDIUM4.3The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side Request Forgery in version...
CVE-2025-8676MEDIUM4.3The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in vers...
CVE-2025-8342HIGH8.1The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypas...
CVE-2025-6025HIGH7.5The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all ver...
CVE-2025-55726Rejected reason: Not used
CVE-2025-55725Rejected reason: Not used
CVE-2025-55724Rejected reason: Not used
CVE-2025-55723Rejected reason: Not used
CVE-2025-55722Rejected reason: Not used
CVE-2025-55721Rejected reason: Not used
CVE-2025-55720Rejected reason: Not used
CVE-2025-55719Rejected reason: Not used
CVE-2025-55718Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now