2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14548MEDIUM6.4The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all ver...
CVE-2025-14163MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-14155MEDIUM5.3The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthor...
CVE-2025-67743MEDIUM6.5Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1...
CVE-2025-68614MEDIUM5.4LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule A...
CVE-2025-68480MEDIUM5.3Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions fro...
CVE-2025-67436MEDIUM6.5Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inj...
CVE-2025-67291MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute a...
CVE-2025-67290MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to e...
CVE-2025-65837MEDIUM5.4PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.
CVE-2025-65790MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file ...
CVE-2025-26787MEDIUM4.7An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CL...
CVE-2025-15033MEDIUM6.5A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on si...
CVE-2025-65270MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote ...
CVE-2025-68333MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix possible deadlock in the deferred_ir...
CVE-2025-67443MEDIUM6.1Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the lo...
CVE-2025-8460MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-54890MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-62880MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery...
CVE-2025-62107MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in PluginOps Feather Login Page feather-login-page allows Cross Site Req...
CVE-2025-62094MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidthemes Void El...
CVE-2025-8305MEDIUM6.5An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen...
CVE-2025-8304MEDIUM6.5An authenticated local user can obtain information that allows claiming security policy rules of another user due to sen...
CVE-2025-15014MEDIUM6.3A security flaw has been discovered in loganhong php loganSite up to c035fb5c3edd0b2a5e32fd4051cbbc9e61a31426. This affe...
CVE-2025-15013MEDIUM5.3A vulnerability was identified in floooh sokol up to 5d11344150973f15e16d3ec4ee7550a73fb995e0. The impacted element is t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now