2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12537MEDIUM6.4The Addon Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to...
CVE-2025-67897MEDIUM5.3In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take adva...
CVE-2025-9873MEDIUM6.4The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,...
CVE-2025-9856MEDIUM6.4The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to St...
CVE-2025-9488MEDIUM6.4The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all ve...
CVE-2025-9207MEDIUM5.3The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2...
CVE-2025-9116MEDIUM5.8The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outp...
CVE-2025-8780MEDIUM6.4The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero ...
CVE-2025-8779MEDIUM6.4The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-8687MEDIUM6.4The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image ...
CVE-2025-8617MEDIUM6.4The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_...
CVE-2025-8199MEDIUM6.4The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee...
CVE-2025-8195MEDIUM6.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Co...
CVE-2025-7960MEDIUM6.4The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing...
CVE-2025-7058MEDIUM6.4The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in a...
CVE-2025-36750MEDIUM5.4ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be di...
CVE-2025-36748MEDIUM5.4ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScr...
CVE-2025-14617MEDIUM5.3A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown func...
CVE-2025-14607MEDIUM6.3A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicom...
CVE-2025-14606MEDIUM5A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the funct...
CVE-2025-14581MEDIUM4.3The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to authorization bypass due to a missing c...
CVE-2025-14540MEDIUM4.3The Userback plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ...
CVE-2025-14539MEDIUM5.4The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in...
CVE-2025-14508MEDIUM6.5The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data de...
CVE-2025-14477MEDIUM4.9The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now