2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13220MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-12398MEDIUM6.1The Product Table for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_k...
CVE-2025-14080MEDIUM5.3The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Missing Authorization in all versions up...
CVE-2025-14054MEDIUM4.4The WC Builder – WooCommerce Page Builder for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-14043MEDIUM5.3The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization c...
CVE-2025-13838MEDIUM6.4The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the '...
CVE-2025-11496MEDIUM6.1The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-7733MEDIUM4.3The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in a...
CVE-2025-14298MEDIUM5.4The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2025-12492MEDIUM5.3The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-12820MEDIUM5.3The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its set...
CVE-2025-14735MEDIUM4.4The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ...
CVE-2025-14734MEDIUM5.4The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-14721MEDIUM5.5The Responsive and Swipe slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rsSli...
CVE-2025-14633MEDIUM5.3The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2025-14168MEDIUM4.3The WP DB Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-14164MEDIUM4.3The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13624MEDIUM6.1The Overstock Affiliate Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PH...
CVE-2025-13365MEDIUM6.1The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-12898MEDIUM5.3The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2025-12581MEDIUM6.1The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up ...
CVE-2025-8065MEDIUM6.5A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6....
CVE-2025-14299MEDIUM6.5The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer over...
CVE-2025-67712MEDIUM4.7There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a re...
CVE-2025-12874MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Mana...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now