2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12112MEDIUM6.4The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad...
CVE-2025-12064MEDIUM6.1The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all v...
CVE-2025-12042MEDIUM5.3The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2025-12000MEDIUM6.5The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in ...
CVE-2025-11972MEDIUM4.9The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection ...
CVE-2025-11748MEDIUM4.3The Groups plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, ...
CVE-2025-12583MEDIUM6.4The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-64495MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. In versions 0.6.34 an...
CVE-2025-64494MEDIUM4.6Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places whe...
CVE-2025-64493MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8....
CVE-2025-64491MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-64485MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.4.0 through 2.48.1...
CVE-2025-12911MEDIUM4.3Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform...
CVE-2025-12910MEDIUM6.2Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain pote...
CVE-2025-12909MEDIUM5.3Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cr...
CVE-2025-12908MEDIUM5.4Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a rem...
CVE-2025-12906MEDIUM5.4Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform...
CVE-2025-12905MEDIUM5.4Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker t...
CVE-2025-64437MEDIUM5KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler doe...
CVE-2025-64436MEDIUM5.3KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the vir...
CVE-2025-64435MEDIUM5.3KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controll...
CVE-2025-64434MEDIUM6.3KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification l...
CVE-2025-64433MEDIUM6.5KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered...
CVE-2025-63420MEDIUM4.1CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created F...
CVE-2025-12418MEDIUM5.6Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now