2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12180MEDIUM4.3The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. T...
CVE-2025-12090MEDIUM6.4The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-...
CVE-2025-12038MEDIUM4.3The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability c...
CVE-2025-11983MEDIUM4.3The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9....
CVE-2025-11740MEDIUM6.5The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to...
CVE-2025-11502MEDIUM6.4The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2025-12118MEDIUM6.4The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions ...
CVE-2025-11927MEDIUM4.4The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cros...
CVE-2025-11377MEDIUM4.3The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,...
CVE-2025-12367MEDIUM4.3The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin...
CVE-2025-11928MEDIUM4.4The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2025-62275MEDIUM5.3Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023....
CVE-2025-11922MEDIUM6.4The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individ...
CVE-2025-11816MEDIUM5.3The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul...
CVE-2025-11174MEDIUM5.3The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and includ...
CVE-2025-62276MEDIUM5.5The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported ver...
CVE-2025-12464MEDIUM6.2A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped ...
CVE-2025-63563MEDIUM6.5Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions...
CVE-2025-63562MEDIUM6.3Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorizati...
CVE-2025-60711MEDIUM6.3Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a n...
CVE-2025-62267MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7....
CVE-2025-12546MEDIUM5.4A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen...
CVE-2025-62264MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, an...
CVE-2025-6075MEDIUM5.5If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env...
CVE-2025-59501MEDIUM4.8Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now