2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-7785MEDIUM4.3A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the fun...
CVE-2025-6227LOW3.1Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which al...
CVE-2025-6233MEDIUM4.9Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths...
CVE-2025-50126MEDIUM5.3A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authent...
CVE-2025-50058MEDIUM5.1A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote auth...
CVE-2025-50057MEDIUM6.9A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote a...
CVE-2025-50056MEDIUM5.1A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote a...
CVE-2025-49486HIGH8.6A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicio...
CVE-2025-49485HIGH8.6A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute ar...
CVE-2025-49484HIGH8.7A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execut...
CVE-2025-2425MEDIUM5.1Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET secu...
CVE-2025-7444CRITICAL9.8The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0...
CVE-2025-6226MEDIUM6.5Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization...
CVE-2025-6197MEDIUM4.2An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites ...
CVE-2025-6023HIGH7.6An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vuln...
CVE-2025-38349HIGH7.8In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still ...
CVE-2025-26855CRITICAL9.8A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL c...
CVE-2025-26854CRITICAL9.8A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQ...
CVE-2025-7772MEDIUM6.5The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F...
CVE-2025-7438HIGH7.5The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid...
CVE-2025-7643CRITICAL9.1The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid...
CVE-2025-6726MEDIUM4.3The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2025-6719MEDIUM4.4The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2025-6718HIGH8.8The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX...
CVE-2025-6717MEDIUM6.5The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and includin...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now