2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10303MEDIUM4.3The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2025-10301MEDIUM4.3The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2025-10300MEDIUM4.3The TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0....
CVE-2025-10194MEDIUM6.4The Shortcode Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortco...
CVE-2025-10186MEDIUM5.3The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized loss ...
CVE-2025-10141MEDIUM6.4The Digiseller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ds' shortcode in all ...
CVE-2025-10140MEDIUM6.4The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' ...
CVE-2025-10139MEDIUM6.4The WP BookWidgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bw_link' shortcod...
CVE-2025-10135MEDIUM6.4The WP ViewSTL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewstl' shortcode in...
CVE-2025-10133MEDIUM6.4The URLYar URL Shortner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'urlyar_short...
CVE-2025-10132MEDIUM6.4The Dhivehi Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dhivehi' shortcode ...
CVE-2025-10056MEDIUM4.4The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin...
CVE-2025-10045MEDIUM4.9The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versio...
CVE-2025-10038MEDIUM6.5The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and includ...
CVE-2025-55039MEDIUM6.5This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 an...
CVE-2025-11161MEDIUM5.4The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading sh...
CVE-2025-11160MEDIUM5.4The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in ...
CVE-2025-8561MEDIUM6.4The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all vers...
CVE-2025-31702MEDIUM6.8A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user cred...
CVE-2025-11176MEDIUM4.3The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2025-10406MEDIUM5.5The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to ...
CVE-2025-55079MEDIUM5.5In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of...
CVE-2025-54278MEDIUM5.5Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to...
CVE-2025-54270MEDIUM5.5Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead t...
CVE-2025-54269MEDIUM5.5Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to mem...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now