2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71201HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early read unlock of page with EOF in mi...
CVE-2025-71200MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-of-dwcmshc: Prevent illegal clock reduct...
CVE-2025-8572CRITICAL9.8The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7...
CVE-2025-6792MEDIUM5.3The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-15483MEDIUM4.4The Link Hopper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hop_name’ parameter in all ve...
CVE-2025-14873MEDIUM4.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Req...
CVE-2025-14852MEDIUM4.3The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-14608MEDIUM5.3The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2025-14067MEDIUM5.3The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec...
CVE-2025-13973MEDIUM5.3The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versi...
CVE-2025-13681MEDIUM4.9The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and includi...
CVE-2025-70957HIGH7.5A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises ...
CVE-2025-70956HIGH7.5A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the...
CVE-2025-70955HIGH7.5A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems ...
CVE-2025-70954HIGH7.5A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025....
CVE-2025-70866HIGH8.8LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User rol...
CVE-2025-69633CRITICAL9.8A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through ...
CVE-2025-15157HIGH8.8The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification...
CVE-2025-68128Rejected reason: reserved but not needed
CVE-2025-68127Rejected reason: reserved but not needed
CVE-2025-68126Rejected reason: reserved but not needed
CVE-2025-68125Rejected reason: reserved but not needed
CVE-2025-68124Rejected reason: reserved but not needed
CVE-2025-58184Rejected reason: reserved but not needed
CVE-2025-58182Rejected reason: reserved but not needed

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now