2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12661MEDIUM6.4The Pollcaster Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter in...
CVE-2025-12660MEDIUM6.4The Padlet Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'key' parameter in the 'w...
CVE-2025-12170MEDIUM5.3The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'w...
CVE-2025-12086MEDIUM4.3The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
CVE-2025-11885MEDIUM6.1The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' parame...
CVE-2025-11815MEDIUM4.3The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz...
CVE-2025-11802MEDIUM6.4The Bulma Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' shortcode attribut...
CVE-2025-11801MEDIUM6.4The AudioTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' shortcode attribute of...
CVE-2025-11800MEDIUM6.4The Surbma | MiniCRM Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode ...
CVE-2025-11799MEDIUM6.4The Affiliate AI Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'asin' shortcode attribu...
CVE-2025-11773MEDIUM4.3The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to un...
CVE-2025-11771MEDIUM5.3The Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO plugin for WordPress is vulnerable to un...
CVE-2025-11770MEDIUM6.4The BrightTALK WordPress Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'format' sh...
CVE-2025-11768MEDIUM6.4The Islamic Phrases plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phrases' shortcode attrib...
CVE-2025-11767MEDIUM6.4The Tips Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tip' shortcode in all vers...
CVE-2025-11765MEDIUM6.4The Stock Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_height' and 'image_widt...
CVE-2025-11764MEDIUM6.4The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in t...
CVE-2025-11763MEDIUM6.4The Display Pages Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column_count' par...
CVE-2025-11003MEDIUM6.4The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz...
CVE-2025-10938MEDIUM6.5The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2025-62687MEDIUM6.9Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unin...
CVE-2025-62189MEDIUM5.3LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administra...
CVE-2025-61949MEDIUM5.4LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information i...
CVE-2025-9825MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 ...
CVE-2025-13499MEDIUM5.5Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now