2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13494MEDIUM5.3The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2025-13362MEDIUM4.3The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0....
CVE-2025-13312MEDIUM5.3The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capabili...
CVE-2025-13006MEDIUM5.3The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in a...
CVE-2025-12417MEDIUM6.4The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-27389MEDIUM5.1A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this is...
CVE-2025-12804MEDIUM6.4The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' ...
CVE-2025-11759MEDIUM4.3The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2025-62223MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker ...
CVE-2025-14052MEDIUM6.5A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function get...
CVE-2025-66563MEDIUM6.1Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user in...
CVE-2025-66561MEDIUM5.4SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting ...
CVE-2025-6946MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi...
CVE-2025-65900MEDIUM6.5Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due...
CVE-2025-65899MEDIUM5.3Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application retu...
CVE-2025-1910MEDIUM6.3The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to e...
CVE-2025-13940MEDIUM5.5An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fir...
CVE-2025-13939MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13938MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13937MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13936MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-12986MEDIUM6When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of service tri...
CVE-2025-66574MEDIUM5.4TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint,...
CVE-2025-66572MEDIUM6.9Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthe...
CVE-2025-66237MEDIUM6.7DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now