2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8383MEDIUM4.3The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4....
CVE-2025-30191MEDIUM5.4Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended act...
CVE-2025-12175MEDIUM4.3The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t...
CVE-2025-12094MEDIUM5.3The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to...
CVE-2025-8385MEDIUM6.8The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is du...
CVE-2025-58152MEDIUM6.9FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection i...
CVE-2025-11191MEDIUM5.3The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the cr...
CVE-2025-11975MEDIUM4.3The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)...
CVE-2025-11806MEDIUM6.4The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all ver...
CVE-2025-48980MEDIUM6.5In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split Vie...
CVE-2025-27208MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker c...
CVE-2025-34283MEDIUM6.5Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Nept...
CVE-2025-34278MEDIUM5.4Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source...
CVE-2025-34273MEDIUM6.5Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administ...
CVE-2025-34272MEDIUM6.5In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the applicatio...
CVE-2025-34270MEDIUM4.9Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fa...
CVE-2025-34135MEDIUM4.4Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. ...
CVE-2025-62265MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupp...
CVE-2025-57109MEDIUM6.5Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When pr...
CVE-2025-52180MEDIUM6.1Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated atta...
CVE-2025-52179MEDIUM6.1Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated at...
CVE-2025-64118MEDIUM6.1node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uni...
CVE-2025-64116MEDIUM6.1Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts...
CVE-2025-64115MEDIUM6.1Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use...
CVE-2025-62266MEDIUM6.1By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 20...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now