2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13629MEDIUM4.3The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-13626MEDIUM6.1The myLCO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter ...
CVE-2025-13358MEDIUM5.3The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing...
CVE-2025-13309MEDIUM4.3The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress ...
CVE-2025-13308MEDIUM5.4The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' para...
CVE-2025-13137MEDIUM6.1The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2025-12721MEDIUM5.3The g-FFL Cockpit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-12720MEDIUM5.3The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization ...
CVE-2025-12717MEDIUM6.4The List Attachments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_list' p...
CVE-2025-12715MEDIUM6.4The Canadian Nutrition Facts Label plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'percentage...
CVE-2025-12577MEDIUM4.3The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized modific...
CVE-2025-12574MEDIUM4.3The Listar – Directory Listing & Classifieds WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of...
CVE-2025-12091MEDIUM4.3The Search, Filters & Merchandising for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2025-13922MEDIUM6.5The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based bli...
CVE-2025-12505MEDIUM5.4The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This ...
CVE-2025-11263MEDIUM6.1The Link Whisper Free plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the type parameter in all...
CVE-2025-66629MEDIUM4.3HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OA...
CVE-2025-14116MEDIUM4.7A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the function OtherEmbedding.ae...
CVE-2025-8148MEDIUM4.2An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with a...
CVE-2025-14105MEDIUM4.3A vulnerability was determined in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. This impacts an unknown function of the ...
CVE-2025-66581MEDIUM6.5Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, ...
CVE-2025-66577MEDIUM5.3cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow...
CVE-2025-66558MEDIUM4.3Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing owne...
CVE-2025-66557MEDIUM4.3Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra...
CVE-2025-66556MEDIUM4.3Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat pe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now