2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6539MEDIUM6.4The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all ...
CVE-2025-6441CRITICAL9.8The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin ...
CVE-2025-6387MEDIUM6.4The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all ve...
CVE-2025-6385MEDIUM6.4The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versio...
CVE-2025-6382MEDIUM6.4The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's taeggie-feed shortco...
CVE-2025-6380CRITICAL9.8The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its o...
CVE-2025-6262MEDIUM6.4The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai s...
CVE-2025-5084MEDIUM6.1The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_...
CVE-2025-4608MEDIUM6.4The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_bu...
CVE-2025-3669MEDIUM6.4The Supreme Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2025-8107MEDIUM6.3In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-lev...
CVE-2025-8009MEDIUM4.9The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in a...
CVE-2025-7745MEDIUM6.9Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
CVE-2025-26397HIGH7.8SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vuln...
CVE-2025-7852CRITICAL9.8The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ima...
CVE-2025-7437CRITICAL9.8The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ...
CVE-2025-7001LOW2.7An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18....
CVE-2025-4976MEDIUM5.3An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 b...
CVE-2025-4968MEDIUM5.4The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple P...
CVE-2025-4395MEDIUM6.8Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with p...
CVE-2025-4394MEDIUM6.8Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with p...
CVE-2025-4393MEDIUM6.5Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to in...
CVE-2025-41240CRITICAL10Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located wit...
CVE-2025-1299MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions start...
CVE-2025-0765MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now