2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10047MEDIUM4.9The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for W...
CVE-2025-41720MEDIUM4.3A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserv...
CVE-2025-12033MEDIUM4.4The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl...
CVE-2025-10588MEDIUM4.3The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2025-10570MEDIUM4.3The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all ...
CVE-2025-5983MEDIUM6.5The Meta Tag Manager WordPress plugin before 3.3 does not restrict which roles can create http-equiv refresh meta tags.
CVE-2025-10651MEDIUM5.5The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in...
CVE-2025-10638MEDIUM5.3The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allo...
CVE-2025-22167MEDIUM6.5This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain ...
CVE-2025-62661MEDIUM6.9Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension, Mediawiki - Growth...
CVE-2025-62592MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62591MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...
CVE-2025-62478MEDIUM4.9Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Object Store). The support...
CVE-2025-62477MEDIUM4.9Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The s...
CVE-2025-62476MEDIUM4.9Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Remote Replication). The s...
CVE-2025-62475MEDIUM4.9Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported versi...
CVE-2025-62289MEDIUM4.9Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supporte...
CVE-2025-62288MEDIUM4.9Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (co...
CVE-2025-62287MEDIUM6.1Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server)....
CVE-2025-61885MEDIUM4.3Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server)....
CVE-2025-61881MEDIUM5.9Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, ...
CVE-2025-61764MEDIUM5.3Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2025-61762MEDIUM6.3Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Payables). The suppor...
CVE-2025-61761MEDIUM5.4Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Orde...
CVE-2025-61759MEDIUM6.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now