2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67344MEDIUM4.6jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.
CVE-2025-67341MEDIUM4.6jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to uploa...
CVE-2025-53960MEDIUM5.9When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., w...
CVE-2025-12843MEDIUM5.5Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.
CVE-2025-36746MEDIUM5.4SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject pay...
CVE-2025-36743MEDIUM6.8SolarEdge SE3680H has an exposed debug/test interface accessible to unauthenticated actors, allowing disclosure of syste...
CVE-2025-14442MEDIUM5.3The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information expos...
CVE-2025-14159MEDIUM4.3The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2025-14065MEDIUM4.3The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability che...
CVE-2025-14030MEDIUM6.4The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all...
CVE-2025-12965MEDIUM6.4The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' par...
CVE-2025-12408MEDIUM5.3The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure i...
CVE-2025-12407MEDIUM4.3The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2025-12841MEDIUM5.3The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of t...
CVE-2025-23408MEDIUM6.5Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The is...
CVE-2025-14074MEDIUM4.3The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to unauthorized post dupl...
CVE-2025-13993MEDIUM5.5The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form...
CVE-2025-12348MEDIUM5.3The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Miss...
CVE-2025-12960MEDIUM6.5The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0...
CVE-2025-67730MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to...
CVE-2025-4970MEDIUM5.5The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2025-14049MEDIUM6.1The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2025-13891MEDIUM6.5The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up t...
CVE-2025-11876MEDIUM6.4The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mailgun_su...
CVE-2025-14356MEDIUM4.3The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now