2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10132MEDIUM6.4The Dhivehi Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dhivehi' shortcode ...
CVE-2025-10056MEDIUM4.4The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin...
CVE-2025-10045MEDIUM4.9The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versio...
CVE-2025-10038MEDIUM6.5The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and includ...
CVE-2025-55039MEDIUM6.5This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 an...
CVE-2025-11161MEDIUM5.4The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading sh...
CVE-2025-11160MEDIUM5.4The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in ...
CVE-2025-8561MEDIUM6.4The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all vers...
CVE-2025-31702MEDIUM6.8A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user cred...
CVE-2025-11176MEDIUM4.3The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2025-10406MEDIUM5.5The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to ...
CVE-2025-55079MEDIUM5.5In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of...
CVE-2025-54278MEDIUM5.5Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to...
CVE-2025-54270MEDIUM5.5Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead t...
CVE-2025-54269MEDIUM5.5Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to mem...
CVE-2025-61797MEDIUM5.4Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha...
CVE-2025-61796MEDIUM5.4Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha...
CVE-2025-54272MEDIUM5.4Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha...
CVE-2025-54196MEDIUM4.3Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerabil...
CVE-2025-54267MEDIUM6.5Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an...
CVE-2025-54266MEDIUM4.8Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a ...
CVE-2025-54265MEDIUM5.9Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an...
CVE-2025-62374MEDIUM6.4Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, inje...
CVE-2025-60540MEDIUM6.5karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF).
CVE-2025-60374MEDIUM6.1Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScrip...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now