2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36746MEDIUM5.4SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject pay...
CVE-2025-36743MEDIUM6.8SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of syste...
CVE-2025-14442MEDIUM5.3The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information expos...
CVE-2025-14159MEDIUM4.3The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2025-14065MEDIUM4.3The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che...
CVE-2025-14030MEDIUM6.4The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all...
CVE-2025-12965MEDIUM6.4The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' par...
CVE-2025-12408MEDIUM5.3The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure i...
CVE-2025-12407MEDIUM4.3The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2025-12841MEDIUM5.3The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of t...
CVE-2025-23408MEDIUM6.5Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The is...
CVE-2025-14074MEDIUM4.3The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post dupl...
CVE-2025-13993MEDIUM5.5The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form...
CVE-2025-12348MEDIUM5.3The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Miss...
CVE-2025-12960MEDIUM6.5The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0...
CVE-2025-67730MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to...
CVE-2025-4970MEDIUM5.5The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2025-14049MEDIUM6.1The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2025-13891MEDIUM6.5The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up t...
CVE-2025-11876MEDIUM6.4The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_su...
CVE-2025-14356MEDIUM4.3The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-13660MEDIUM5.3The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to, and including, 1.2.3. T...
CVE-2025-12655MEDIUM5.3The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write via a missing authoriza...
CVE-2025-67724MEDIUM6.1Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason ...
CVE-2025-10684MEDIUM4.3The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX ac...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now