2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62961MEDIUM5.4Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured ...
CVE-2025-62960MEDIUM5.4Missing Authorization vulnerability in sparklewpthemes Construction Light construction-light allows Exploiting Incorrect...
CVE-2025-64723MEDIUM4.4Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with ...
CVE-2025-63390MEDIUM5.3An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fa...
CVE-2025-14823MEDIUM5.3In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure...
CVE-2025-9787MEDIUM6.1Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulne...
CVE-2025-7047MEDIUM5.4Missing Authorization vulnerability in Utarit Informatics Services Inc. SoliClub allows Privilege Abuse. This issue aff...
CVE-2025-14744MEDIUM6.5Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, poten...
CVE-2025-65000MEDIUM5.3SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2...
CVE-2025-40893MEDIUM6.1A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of netwo...
CVE-2025-40891MEDIUM4.7A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper val...
CVE-2025-14618MEDIUM4.3The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data du...
CVE-2025-14277MEDIUM4.3The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all version...
CVE-2025-13110MEDIUM4.3The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2025-40602MEDIUM6.6A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme...
CVE-2025-64997MEDIUM6.5Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view...
CVE-2025-13730MEDIUM6.4The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'op...
CVE-2025-67546MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Ret...
CVE-2025-66104MEDIUM6.5Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exp...
CVE-2025-66100MEDIUM6.5Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Acces...
CVE-2025-66068MEDIUM6.5Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured ...
CVE-2025-64375MEDIUM6.5Missing Authorization vulnerability in Mahmudul Hasan Arif WP Social Ninja wp-social-reviews allows Exploiting Incorrect...
CVE-2025-64295MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack a...
CVE-2025-64273MEDIUM6.5Missing Authorization vulnerability in GetResponse Email marketing for WordPress by GetResponse Official getresponse-off...
CVE-2025-64272MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in GetResponse Email marketing ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now