2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13854MEDIUM6.4The Curved Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'radius' parameter of the arct...
CVE-2025-13852MEDIUM6.4The Debt.com Business in a Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configuration'...
CVE-2025-13717MEDIUM5.3The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa...
CVE-2025-13704MEDIUM6.4The Autogen Headers Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head_class' paramete...
CVE-2025-13701MEDIUM6.1The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] para...
CVE-2025-11453MEDIUM6.4The Header and Footer Scripts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _inpost_head_scr...
CVE-2025-9222MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and...
CVE-2025-64093CRITICAL9.8Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname...
CVE-2025-64092HIGH7.5This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly qu...
CVE-2025-64091HIGH8.8This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.
CVE-2025-64090HIGH8.8This vulnerability allows authenticated attackers to execute commands via the hostname of the device.
CVE-2025-3950LOW3.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 1...
CVE-2025-13900MEDIUM6.4The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wp...
CVE-2025-13895MEDIUM6.1The Top Position Google Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['...
CVE-2025-13853MEDIUM6.4The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter o...
CVE-2025-13781MEDIUM6.5GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7...
CVE-2025-13772MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7...
CVE-2025-13761CRITICAL9.6GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 th...
CVE-2025-13729MEDIUM6.4The Entry Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'entry-views' shortco...
CVE-2025-11246MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 1...
CVE-2025-10569MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18...
CVE-2025-69195HIGH8.8A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization lo...
CVE-2025-69194CRITICAL9.8A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validat...
CVE-2025-14937HIGH7.2The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parame...
CVE-2025-14741CRITICAL9.1The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modifi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now