2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12822MEDIUM4.3The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-12814MEDIUM5.3The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect ...
CVE-2025-12751MEDIUM4.3The WSChat – WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2025-12710MEDIUM6.4The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shor...
CVE-2025-12359MEDIUM5.4The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t...
CVE-2025-12174MEDIUM6.5The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to...
CVE-2025-12349MEDIUM5.3The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Auth...
CVE-2025-6251MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['fi...
CVE-2025-12777MEDIUM5.3The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl...
CVE-2025-12770MEDIUM5.3The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and inclu...
CVE-2025-12427MEDIUM5.3The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ...
CVE-2025-13225MEDIUM6Tanium addressed an arbitrary file deletion vulnerability in TanOS.
CVE-2025-65093MEDIUM5.5LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based ...
CVE-2025-65013MEDIUM6.1LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cros...
CVE-2025-65012MEDIUM5.4Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any...
CVE-2025-64515MEDIUM4.3Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data ...
CVE-2025-54990MEDIUM5.3XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users with...
CVE-2025-63229MEDIUM5.4The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting ...
CVE-2025-63226MEDIUM5.7The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking...
CVE-2025-63749MEDIUM6.5pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.
CVE-2025-63693MEDIUM5.4The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping fo...
CVE-2025-61664MEDIUM4.9A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free iss...
CVE-2025-61663MEDIUM4.9A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (...
CVE-2025-61661MEDIUM4.8A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootl...
CVE-2025-56499MEDIUM6.5Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now