2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2579MEDIUM6.4The Lottie Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up ...
CVE-2025-2543MEDIUM6.4The Advanced Accordion Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up...
CVE-2025-1284MEDIUM4.3The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable...
CVE-2025-1908HIGH7.7An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potential...
CVE-2025-0639HIGH7.5An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions fro...
CVE-2025-41423MEDIUM4.3Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the ...
CVE-2025-41395HIGH7.5Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by th...
CVE-2025-3761HIGH8.8The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions u...
CVE-2025-35965HIGH7.5Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity o...
CVE-2025-32730MEDIUM6.8Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., ...
CVE-2025-2558HIGH8.6The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to ...
CVE-2025-1453MEDIUM4.8The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could ...
CVE-2025-3435MEDIUM4.4The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_foote...
CVE-2025-46381Rejected reason: Not used
CVE-2025-46380Rejected reason: Not used
CVE-2025-46379Rejected reason: Not used
CVE-2025-46378Rejected reason: Not used
CVE-2025-46377Rejected reason: Not used
CVE-2025-46376Rejected reason: Not used
CVE-2025-46375Rejected reason: Not used
CVE-2025-46374Rejected reason: Not used
CVE-2025-1976MEDIUM6.7Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can ...
CVE-2025-46419MEDIUM5.9Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.
CVE-2025-46417HIGH7.5The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltra...
CVE-2025-27581MEDIUM4.3NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now