2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6681MEDIUM6.4The Fan Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions...
CVE-2025-26400MEDIUM6.5SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could ...
CVE-2025-53082CRITICAL9.1An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unin...
CVE-2025-53081CRITICAL9.1An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in uninte...
CVE-2025-8264CRITICAL9Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in...
CVE-2025-6495HIGH7.5The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and inc...
CVE-2025-53649MEDIUM5.9"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V...
CVE-2025-53080MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) al...
CVE-2025-53079MEDIUM4.9Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sen...
CVE-2025-53078CRITICAL9.8Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via ...
CVE-2025-53077MEDIUM6.5An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without...
CVE-2025-4566MEDIUM6.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-4370MEDIUM5.3The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on proc...
CVE-2025-3075MEDIUM5.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-7811MEDIUM6.4The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2025-7810MEDIUM5.4The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'd...
CVE-2025-7809MEDIUM6.4The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2025-54666Rejected reason: Not used
CVE-2025-54665Rejected reason: Not used
CVE-2025-54664Rejected reason: Not used
CVE-2025-54663Rejected reason: Not used
CVE-2025-54662Rejected reason: Not used
CVE-2025-54661Rejected reason: Not used
CVE-2025-54769HIGH8.8An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in...
CVE-2025-54768MEDIUM5.3An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now