2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14061MEDIUM5.3The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C...
CVE-2025-13750MEDIUM4.3The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modif...
CVE-2025-14154MEDIUM6.1The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2025-64700MEDIUM5.1Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logg...
CVE-2025-14385MEDIUM6.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all ve...
CVE-2025-13880MEDIUM6.5The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and...
CVE-2025-13861MEDIUM6.1The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scriptin...
CVE-2025-11775MEDIUM4.8An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by ...
CVE-2025-14304MEDIUM6.8Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanis...
CVE-2025-13977MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2025-14302MEDIUM6.8Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not...
CVE-2025-14801MEDIUM4.8A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of th...
CVE-2025-11369MEDIUM4.3The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unau...
CVE-2025-11009MEDIUM5.1Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all vers...
CVE-2025-34288MEDIUM6.7Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between s...
CVE-2025-64520MEDIUM4.3GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unau...
CVE-2025-14466MEDIUM6.9A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthe...
CVE-2025-13532MEDIUM6.2Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the sele...
CVE-2025-68150MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2025-68146MEDIUM6.5filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTO...
CVE-2025-65592MEDIUM6.1nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloa...
CVE-2025-65591MEDIUM5.4nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.
CVE-2025-65590MEDIUM5.4nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Managemen...
CVE-2025-68142MEDIUM5.3PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a R...
CVE-2025-65589MEDIUM6.1nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now