2025 CVE Vulnerabilities

45,259 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-6236MEDIUM4.8The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2025-6234MEDIUM6.1The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2025-53753Rejected reason: Not used
CVE-2025-53752Rejected reason: Not used
CVE-2025-53751Rejected reason: Not used
CVE-2025-53750Rejected reason: Not used
CVE-2025-53749Rejected reason: Not used
CVE-2025-53748Rejected reason: Not used
CVE-2025-53747Rejected reason: Not used
CVE-2025-53746Rejected reason: Not used
CVE-2025-46406MEDIUM5.6A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high l...
CVE-2025-44003MEDIUM4.3Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with ...
CVE-2025-35983MEDIUM6.5Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged atta...
CVE-2025-5807MEDIUM6.1The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ param...
CVE-2025-4406MEDIUM5.4The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ...
CVE-2025-6976MEDIUM5.4The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-6975MEDIUM6.1The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2025-6970HIGH7.5The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injecti...
CVE-2025-0646Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-0141HIGH8.4An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on enables a locally authen...
CVE-2025-0140MEDIUM6.8An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ...
CVE-2025-0139MEDIUM6.3An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a loc...
CVE-2025-6377HIGH7.8A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Sim...
CVE-2025-6376HIGH7.8A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Sim...
CVE-2025-53624CRITICAL10The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docus...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now