2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12123MEDIUM6.1The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...
CVE-2025-3784MEDIUM5.5Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose creden...
CVE-2025-12151MEDIUM6.4The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in...
CVE-2025-13762MEDIUM4.8Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial...
CVE-2025-12713MEDIUM6.4The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all v...
CVE-2025-12712MEDIUM6.4The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up...
CVE-2025-12670MEDIUM6.4The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic...
CVE-2025-12666MEDIUM6.4The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin...
CVE-2025-12649MEDIUM6.4The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sortt...
CVE-2025-12579MEDIUM5.3The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2025-12578MEDIUM4.3The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-66030MEDIUM5.3Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overfl...
CVE-2025-7449MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18...
CVE-2025-6195MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6...
CVE-2025-65670MEDIUM4.3An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpo...
CVE-2025-13611MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 tha...
CVE-2025-12653MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 1...
CVE-2025-65676MEDIUM5.4Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi...
CVE-2025-65675MEDIUM5.4Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi...
CVE-2025-65239MEDIUM4.3Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13....
CVE-2025-65238MEDIUM6.5Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6....
CVE-2025-65237MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to e...
CVE-2025-63938MEDIUM6.5Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs....
CVE-2025-9191MEDIUM6.3The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via des...
CVE-2025-9163MEDIUM6.1The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now