2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5338MEDIUM5.4The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all...
CVE-2025-52934Rejected reason: Not a vulnerability.
CVE-2025-5459HIGH8.8A user with specific node group editing permissions and a specially crafted class parameter could be used to execute com...
CVE-2025-5846MEDIUM4.3An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1...
CVE-2025-5315MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18...
CVE-2025-48497MEDIUM5.1Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a speci...
CVE-2025-41404MEDIUM5.3Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is e...
CVE-2025-3279MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18...
CVE-2025-37101HIGH8.7A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability cou...
CVE-2025-2938HIGH8.8An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18...
CVE-2025-1754MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18...
CVE-2025-6624HIGH7.2Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through ...
CVE-2025-6546MEDIUM5.4The Drive Folder Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tablecssclass’ para...
CVE-2025-6540MEDIUM6.4The web-cam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter in all versions u...
CVE-2025-6537MEDIUM5.4The Namasha By Mdesign plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘playicon_title’ parame...
CVE-2025-5932MEDIUM4.3The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2025-5929MEDIUM5.4The The Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘clientId’ parameter in all ...
CVE-2025-5813MEDIUM5.3The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2025-5275MEDIUM4The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2025-6538MEDIUM5.4The Post Rating and Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter i...
CVE-2025-6383MEDIUM5.4The WP-PhotoNav plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's photonav shortcode in...
CVE-2025-6378MEDIUM6.4The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's di...
CVE-2025-6290MEDIUM5.4The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bra...
CVE-2025-6258MEDIUM6.4The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track short...
CVE-2025-5812MEDIUM4.3The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now