2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12971MEDIUM4.3The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul...
CVE-2025-59454MEDIUM4.3In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResour...
CVE-2025-59302MEDIUM4.7In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following ...
CVE-2025-54057MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This ...
CVE-2025-13742MEDIUM6.1Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used ...
CVE-2025-10476MEDIUM4.3The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-59026MEDIUM5.4Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend...
CVE-2025-59025MEDIUM6.1Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the us...
CVE-2025-30190MEDIUM5.4Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can ...
CVE-2025-30186MEDIUM5.4Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend...
CVE-2025-13381MEDIUM5.3The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due t...
CVE-2025-13378MEDIUM6.5The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forge...
CVE-2025-12584MEDIUM5.3The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc...
CVE-2025-13441MEDIUM5.3The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versio...
CVE-2025-13157MEDIUM5.3The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions...
CVE-2025-13525MEDIUM6.1The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter i...
CVE-2025-13143MEDIUM4.3The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2025-12185MEDIUM4.4The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to...
CVE-2025-12123MEDIUM6.1The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...
CVE-2025-3784MEDIUM5.5Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose creden...
CVE-2025-12151MEDIUM6.4The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in...
CVE-2025-13762MEDIUM4.8Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial...
CVE-2025-12713MEDIUM6.4The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all v...
CVE-2025-12712MEDIUM6.4The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up...
CVE-2025-12670MEDIUM6.4The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now