2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12353MEDIUM5.3The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for ...
CVE-2025-12193MEDIUM6.1The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mp' parameter in all ver...
CVE-2025-12177MEDIUM5.3The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the d...
CVE-2025-12167MEDIUM4.3The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-12125MEDIUM4.4The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm...
CVE-2025-12112MEDIUM6.4The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad...
CVE-2025-12064MEDIUM6.1The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all v...
CVE-2025-12042MEDIUM5.3The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2025-12000MEDIUM6.5The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in ...
CVE-2025-11972MEDIUM4.9The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection ...
CVE-2025-11748MEDIUM4.3The Groups plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, ...
CVE-2025-12583MEDIUM6.4The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-64495MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. In versions 0.6.34 an...
CVE-2025-64494MEDIUM4.6Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places whe...
CVE-2025-64493MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8....
CVE-2025-64491MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14....
CVE-2025-64485MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.4.0 through 2.48.1...
CVE-2025-12911MEDIUM4.3Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform...
CVE-2025-12910MEDIUM6.2Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain pote...
CVE-2025-12909MEDIUM5.3Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cr...
CVE-2025-12908MEDIUM5.4Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a rem...
CVE-2025-12906MEDIUM5.4Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform...
CVE-2025-12905MEDIUM5.4Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker t...
CVE-2025-64437MEDIUM5KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler doe...
CVE-2025-64436MEDIUM5.3KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the vir...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now