2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-49903MEDIUM5.3Missing Authorization vulnerability in bdthemes ZoloBlocks zoloblocks allows Exploiting Incorrectly Configured Access Co...
CVE-2025-49899MEDIUM5.3Missing Authorization vulnerability in jjlemstra Whydonate wp-whydonate allows Accessing Functionality Not Properly Cons...
CVE-2025-49377MEDIUM6.3Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Acc...
CVE-2025-49376MEDIUM5.3Missing Authorization vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Accessing Functionality Not Properly Const...
CVE-2025-49374MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows Server Side Request Forgery....
CVE-2025-49373MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-p...
CVE-2025-48099MEDIUM4.7Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forg...
CVE-2025-48096MEDIUM6.5Missing Authorization vulnerability in FRESHFACE Custom CSS custom-css-editor allows Exploiting Incorrectly Configured A...
CVE-2025-48095MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak...
CVE-2025-11966MEDIUM6.4In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory n...
CVE-2025-8848MEDIUM5.4A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a ...
CVE-2025-11844MEDIUM5.4Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function loca...
CVE-2025-11750MEDIUM5.3In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning d...
CVE-2025-11411MEDIUM5.7NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RR...
CVE-2025-6833MEDIUM4.3The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Inse...
CVE-2025-11915MEDIUM6.9Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in f...
CVE-2025-41109MEDIUM4.6Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. T...
CVE-2025-11952MEDIUM6.1Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co...
CVE-2025-11883MEDIUM6.4The Responsive Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rprogress...
CVE-2025-11880MEDIUM6.4The SM CountDown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's smcountdown s...
CVE-2025-11878MEDIUM6.4The ST Categories Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's st-categorie...
CVE-2025-11872MEDIUM6.4The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2025-11870MEDIUM6.4The Simple Business Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'simple_business_data' sh...
CVE-2025-11867MEDIUM6.4The Bg Book Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `book_author` post meta,...
CVE-2025-11866MEDIUM6.4The Photographers galleries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode att...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now