2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5234MEDIUM5.4The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in a...
CVE-2025-5071HIGH8.8The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing ...
CVE-2025-49763HIGH7.5ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if maliciou...
CVE-2025-31698HIGH7.5ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users ...
CVE-2025-4965MEDIUM5.4The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2025-4571MEDIUM5.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modifi...
CVE-2025-5490MEDIUM4.8The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u...
CVE-2025-5524MEDIUM4.9The OceanWP theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Select HTML tag in all versions up ...
CVE-2025-52474CRITICAL9.8WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerability was identified...
CVE-2025-50201CRITICAL9.8WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was id...
CVE-2025-4479MEDIUM5.4The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-4367MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashbo...
CVE-2025-6201MEDIUM6.4The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is...
CVE-2025-52467CRITICAL9.1pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to c...
CVE-2025-50183MEDIUM6.5OpenList Frontend is a UI component for OpenList. Prior to version 4.0.0-rc.4, a vulnerability exists in the file previe...
CVE-2025-4661LOW2.3A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain acces...
CVE-2025-50182MEDIUM6.1urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does no...
CVE-2025-50181MEDIUM6.1urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all r...
CVE-2025-24291MEDIUM6.1The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the J...
CVE-2025-24288CRITICAL9.8The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default ...
CVE-2025-24287MEDIUM6.1A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the l...
CVE-2025-24286MEDIUM4.9A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute ...
CVE-2025-23173HIGH7.5The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the D...
CVE-2025-23172HIGH7.2The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP e...
CVE-2025-23171HIGH7.2The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now