2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40570LOW2.4A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V10.0), SIPROTEC 5 6MD85 (CP300) (All ve...
CVE-2025-33023MEDIUM5.1A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGE...
CVE-2025-30034MEDIUM5.5A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected devices do not prop...
CVE-2025-30033HIGH7.8The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when...
CVE-2025-43736MEDIUM4.3A Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP...
CVE-2025-8885MEDIUM6.3Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on...
CVE-2025-41686HIGH7.8A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain admin...
CVE-2025-26398MEDIUM6.4SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnera...
CVE-2025-8874MEDIUM6.4The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ...
CVE-2025-8767MEDIUM4.8The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16...
CVE-2025-8482MEDIUM4.3The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This ...
CVE-2025-8418HIGH8.8The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all v...
CVE-2025-47444MEDIUM5.3Missing Authorization vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Exploiting Incorrectly ...
CVE-2025-8081MEDIUM4.9The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via...
CVE-2025-6253HIGH7.5The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in ...
CVE-2025-3892MEDIUM6.7ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerabil...
CVE-2025-30027MEDIUM6.7An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vuln...
CVE-2025-8314MEDIUM6.4The Software Issue Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg param...
CVE-2025-8059CRITICAL9.8The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input ...
CVE-2025-7622MEDIUM5.7During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated...
CVE-2025-8690MEDIUM6.4The Simple Responsive Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an...
CVE-2025-8688MEDIUM6.4The Inline Stock Quotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock shortco...
CVE-2025-8685MEDIUM6.4The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortc...
CVE-2025-8621MEDIUM6.4The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c’ parameter in all vers...
CVE-2025-8568MEDIUM6.4The GMap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘h’ parameter in all versio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now