2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5234 | MEDIUM | 5.4 | 0.2% | Jun 19, 2025 | The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in a... |
| CVE-2025-5071 | HIGH | 8.8 | 0.6% | Jun 19, 2025 | The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing ... |
| CVE-2025-49763 | HIGH | 7.5 | 0.6% | Jun 19, 2025 | ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if maliciou... |
| CVE-2025-31698 | HIGH | 7.5 | 0.4% | Jun 19, 2025 | ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users ... |
| CVE-2025-4965 | MEDIUM | 5.4 | 0.2% | Jun 19, 2025 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2025-4571 | MEDIUM | 5.4 | 0.3% | Jun 19, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modifi... |
| CVE-2025-5490 | MEDIUM | 4.8 | 0.2% | Jun 19, 2025 | The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... |
| CVE-2025-5524 | MEDIUM | 4.9 | 0.2% | Jun 19, 2025 | The OceanWP theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Select HTML tag in all versions up ... |
| CVE-2025-52474 | CRITICAL | 9.8 | 0.4% | Jun 19, 2025 | WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerability was identified... |
| CVE-2025-50201 | CRITICAL | 9.8 | 4.9% | Jun 19, 2025 | WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was id... |
| CVE-2025-4479 | MEDIUM | 5.4 | 0.2% | Jun 19, 2025 | The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-4367 | MEDIUM | 5.4 | 0.2% | Jun 19, 2025 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashbo... |
| CVE-2025-6201 | MEDIUM | 6.4 | 0.2% | Jun 19, 2025 | The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is... |
| CVE-2025-52467 | CRITICAL | 9.1 | 0.3% | Jun 19, 2025 | pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to c... |
| CVE-2025-50183 | MEDIUM | 6.5 | 0.3% | Jun 19, 2025 | OpenList Frontend is a UI component for OpenList. Prior to version 4.0.0-rc.4, a vulnerability exists in the file previe... |
| CVE-2025-4661 | LOW | 2.3 | 0.2% | Jun 19, 2025 | A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain acces... |
| CVE-2025-50182 | MEDIUM | 6.1 | 0.3% | Jun 19, 2025 | urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does no... |
| CVE-2025-50181 | MEDIUM | 6.1 | 0.4% | Jun 19, 2025 | urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all r... |
| CVE-2025-24291 | MEDIUM | 6.1 | 0.4% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the J... |
| CVE-2025-24288 | CRITICAL | 9.8 | 0.4% | Jun 19, 2025 | The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default ... |
| CVE-2025-24287 | MEDIUM | 6.1 | 0.2% | Jun 19, 2025 | A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the l... |
| CVE-2025-24286 | MEDIUM | 4.9 | 10.7% | Jun 19, 2025 | A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute ... |
| CVE-2025-23173 | HIGH | 7.5 | 0.6% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the D... |
| CVE-2025-23172 | HIGH | 7.2 | 1.0% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP e... |
| CVE-2025-23171 | HIGH | 7.2 | 0.5% | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now