2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8467CRITICAL9.8A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnera...
CVE-2025-8488MEDIUM4.3The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to una...
CVE-2025-6722MEDIUM5.3The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive I...
CVE-2025-8466CRITICAL9.8A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an un...
CVE-2025-8400MEDIUM6.1The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ...
CVE-2025-8399MEDIUM6.4The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in...
CVE-2025-8391MEDIUM6.4The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in al...
CVE-2025-6832MEDIUM6.1The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Refl...
CVE-2025-8317MEDIUM6.4The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all...
CVE-2025-8212MEDIUM6.4The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typew...
CVE-2025-8152MEDIUM5.3The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modifi...
CVE-2025-6754HIGH8.8The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both t...
CVE-2025-6626MEDIUM4.4The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-...
CVE-2025-4588MEDIUM6.4The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortc...
CVE-2025-8146MEDIUM6.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut T...
CVE-2025-7694HIGH7.5The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ...
CVE-2025-6078MEDIUM5.4Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on...
CVE-2025-6077CRITICAL9.8Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and ...
CVE-2025-6076HIGH8.8Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "repor...
CVE-2025-54796HIGH7.5Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows...
CVE-2025-54790MEDIUM6.5Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have ...
CVE-2025-54789MEDIUM6.1Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functi...
CVE-2025-54782HIGH8.8Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remo...
CVE-2025-54781LOW2.8Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelbla...
CVE-2025-54386CRITICAL9.8Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now