2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49979MEDIUM4.3Missing Authorization vulnerability in slui Media Hygiene media-hygiene allows Exploiting Incorrectly Configured Access ...
CVE-2025-49978MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch wp-jobsearch allows Exploiting Incorr...
CVE-2025-49977MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross S...
CVE-2025-49976MEDIUM4.3Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-49975MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This iss...
CVE-2025-49974MEDIUM4.3Missing Authorization vulnerability in upstreamplugin UpStream: a Project Management Plugin for WordPress upstream allow...
CVE-2025-49973MEDIUM4.3Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Siz...
CVE-2025-49972MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy tm-replace-howdy allows Cross Site Reques...
CVE-2025-49971MEDIUM4.3Missing Authorization vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Exploiting ...
CVE-2025-49970MEDIUM4.3Missing Authorization vulnerability in sparklewpthemes Hello FSE Blog hello-fse-blog allows Exploiting Incorrectly Confi...
CVE-2025-49969MEDIUM4.3Missing Authorization vulnerability in Zara 4 Zara 4 Image Compression zara-4 allows Exploiting Incorrectly Configured A...
CVE-2025-49968MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Oganro XML Travel Portal Widget oganro-reservation-widget allows Cros...
CVE-2025-49967MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in marcusjansen Live Sports Streamthunder live-sports-streamthunder allo...
CVE-2025-49966MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Oganro Oganro Travel Portal Search Widget for HotelBeds APITUDE API o...
CVE-2025-49965MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Oganro PixelBeds Channel Manager and Hotel Booking Engine pixelbeds-c...
CVE-2025-49964MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in indgeek ClipLink cliplink allows Cross Site Request Forgery.This issu...
CVE-2025-49873HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi e...
CVE-2025-46179CRITICAL9.8A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx pa...
CVE-2025-3319CRITICAL9.8IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session aut...
CVE-2025-3228MEDIUM4.3Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr...
CVE-2025-3227MEDIUM4.3Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr...
CVE-2025-6344CRITICAL9.8A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulne...
CVE-2025-6343CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. Affected is an unkn...
CVE-2025-6342CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. This issue aff...
CVE-2025-48706CRITICAL9.1An issue was discovered in COROS PACE 3 through 3.0808.0. Due to an out-of-bounds read vulnerability, sending a crafted ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now