2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61430MEDIUM6.5Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server ...
CVE-2025-60936MEDIUM6.1Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated atta...
CVE-2025-56438MEDIUM6.8An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically...
CVE-2025-46425MEDIUM6.5Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entit...
CVE-2025-46185MEDIUM6.2An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via...
CVE-2025-11576MEDIUM4.3The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV In...
CVE-2025-5605MEDIUM5.3An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor wit...
CVE-2025-5350MEDIUM4.8SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was a...
CVE-2025-12136MEDIUM6.8The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery...
CVE-2025-12134MEDIUM5.3The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for Wo...
CVE-2025-12096MEDIUM6.4The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr...
CVE-2025-12072MEDIUM4.3The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-12017MEDIUM6.1The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet...
CVE-2025-12016MEDIUM4.4The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' pa...
CVE-2025-12014MEDIUM4.3The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-11992MEDIUM6.1The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-11887MEDIUM4.3The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2025-11257MEDIUM4.3The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2025-11172MEDIUM4.3The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-10902MEDIUM4.3The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabilit...
CVE-2025-10901MEDIUM4.3The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil...
CVE-2025-10749MEDIUM5.4The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in...
CVE-2025-10748MEDIUM6.5The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and inc...
CVE-2025-10740MEDIUM6.3The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid...
CVE-2025-10701MEDIUM6.4The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now