2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14744MEDIUM6.5Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, poten...
CVE-2025-65000MEDIUM5.3SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2...
CVE-2025-40893MEDIUM6.1A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of netwo...
CVE-2025-40891MEDIUM4.7A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper val...
CVE-2025-14618MEDIUM4.3The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data du...
CVE-2025-14277MEDIUM4.3The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all version...
CVE-2025-13110MEDIUM4.3The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2025-40602MEDIUM6.6A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme...
CVE-2025-64997MEDIUM6.5Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view...
CVE-2025-13730MEDIUM6.4The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'op...
CVE-2025-67546MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Ret...
CVE-2025-66104MEDIUM6.5Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exp...
CVE-2025-66100MEDIUM6.5Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Acces...
CVE-2025-66068MEDIUM6.5Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured ...
CVE-2025-64375MEDIUM6.5Missing Authorization vulnerability in Mahmudul Hasan Arif WP Social Ninja wp-social-reviews allows Exploiting Incorrect...
CVE-2025-64295MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack a...
CVE-2025-64273MEDIUM6.5Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-off...
CVE-2025-64272MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing ...
CVE-2025-64270MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS le...
CVE-2025-64225MEDIUM6.5Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Stockie Extra st...
CVE-2025-64192MEDIUM6.3Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2025-63039MEDIUM6.5Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Acces...
CVE-2025-60088MEDIUM6.5Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incor...
CVE-2025-60070MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This i...
CVE-2025-60068MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code In...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now