2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14663MEDIUM4.8A vulnerability was determined in code-projects Student File Management System 1.0. This vulnerability affects unknown c...
CVE-2025-14662MEDIUM5.4A vulnerability was found in code-projects Student File Management System 1.0. This affects an unknown part of the file ...
CVE-2025-14660MEDIUM5.6A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of...
CVE-2025-12696MEDIUM5.3The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting...
CVE-2025-12537MEDIUM6.4The Addon Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to...
CVE-2025-67897MEDIUM5.3In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take adva...
CVE-2025-9873MEDIUM6.4The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,...
CVE-2025-9856MEDIUM6.4The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to St...
CVE-2025-9488MEDIUM6.4The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data’ parameter in all ve...
CVE-2025-9207MEDIUM5.3The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2...
CVE-2025-9116MEDIUM5.8The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outp...
CVE-2025-8780MEDIUM6.4The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero ...
CVE-2025-8779MEDIUM6.4The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-8687MEDIUM6.4The Enter Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown and Image ...
CVE-2025-8617MEDIUM6.4The YITH WooCommerce Quick View plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's yith_...
CVE-2025-8199MEDIUM6.4The MarqueeAddons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Testimonial Marquee...
CVE-2025-8195MEDIUM6.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Co...
CVE-2025-7960MEDIUM6.4The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing...
CVE-2025-7058MEDIUM6.4The Kingcabs theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in a...
CVE-2025-36750MEDIUM5.4ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be di...
CVE-2025-36748MEDIUM5.4ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the local configuration web server. The JavaScr...
CVE-2025-14617MEDIUM5.3A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown func...
CVE-2025-14607MEDIUM6.3A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicom...
CVE-2025-14606MEDIUM5A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5. Affected by this vulnerability is the funct...
CVE-2025-14581MEDIUM4.3The HAPPY – Helpdesk Support Ticket System plugin for WordPress is vulnerable to authorization bypass due to a missing c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now