2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64294MEDIUM5.3Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Co...
CVE-2025-12626MEDIUM4.3A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects...
CVE-2025-12616MEDIUM5.9A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onp...
CVE-2025-6988MEDIUM6.4The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a...
CVE-2025-12137MEDIUM4.9The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Re...
CVE-2025-12180MEDIUM4.3The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. T...
CVE-2025-12090MEDIUM6.4The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-...
CVE-2025-12038MEDIUM4.3The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability c...
CVE-2025-11983MEDIUM4.3The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9....
CVE-2025-11740MEDIUM6.5The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to...
CVE-2025-11502MEDIUM6.4The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2025-12118MEDIUM6.4The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions ...
CVE-2025-11927MEDIUM4.4The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cros...
CVE-2025-11377MEDIUM4.3The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,...
CVE-2025-12367MEDIUM4.3The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin...
CVE-2025-11928MEDIUM4.4The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2025-62275MEDIUM5.3Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023....
CVE-2025-11922MEDIUM6.4The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individ...
CVE-2025-11816MEDIUM5.3The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul...
CVE-2025-11174MEDIUM5.3The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and includ...
CVE-2025-62276MEDIUM5.5The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported ver...
CVE-2025-12464MEDIUM6.2A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped ...
CVE-2025-63563MEDIUM6.5Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions...
CVE-2025-63562MEDIUM6.3Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorizati...
CVE-2025-60711MEDIUM6.3Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a n...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now