2025 CVE Vulnerabilities

45,264 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-28963MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Req...
CVE-2025-28957MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez ...
CVE-2025-28951CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allow...
CVE-2025-27358MEDIUM4.6Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Man...
CVE-2025-27326MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gal...
CVE-2025-26591MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam WP fancy...
CVE-2025-24764MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones (Simply) ...
CVE-2025-24757MEDIUM5.3Missing Authorization vulnerability in AndonDesign uDesign udesign.This issue affects uDesign: from n/a through <= 4.11....
CVE-2025-24748MEDIUM5.3Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.
CVE-2025-24735HIGH7.7Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live...
CVE-2025-23972MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Brian S. Reed Contact Form 7 reCAPTCHA contact-form-7-recaptcha allow...
CVE-2025-6673MEDIUM6.4The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_...
CVE-2025-53600HIGH7.5Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment.
CVE-2025-53599CRITICAL9.8Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted java...
CVE-2025-32918HIGH8.8Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions...
CVE-2025-6944MEDIUM6.4The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and ...
CVE-2025-5372HIGH8.8A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function r...
CVE-2025-7053MEDIUM6.1A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown pro...
CVE-2025-7046MEDIUM5.4The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2025-6814HIGH7.5The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the...
CVE-2025-6787MEDIUM5.4The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartdocs_search' sho...
CVE-2025-6786MEDIUM5.3The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, ...
CVE-2025-6783HIGH7.5The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() functi...
CVE-2025-6782HIGH7.5The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm(...
CVE-2025-6739MEDIUM6.5The WPQuiz plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'wpquiz' shortcode in all v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now