2025 CVE Vulnerabilities

45,152 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10165MEDIUM6.4The AP Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adv_parallax_back'...
CVE-2025-10053MEDIUM4.4The TableGen – Data Table Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings...
CVE-2025-0876MEDIUM4.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Isin Basi A...
CVE-2025-61599MEDIUM5.4Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitte...
CVE-2025-61597MEDIUM5.4Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored ...
CVE-2025-61589MEDIUM5.9Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows ...
CVE-2025-11241MEDIUM6.4The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to ...
CVE-2025-61606MEDIUM6.1WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open R...
CVE-2025-54088MEDIUM6.1CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the c...
CVE-2025-56019MEDIUM6.5An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobil...
CVE-2025-60661MEDIUM5.3Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWa...
CVE-2025-59406MEDIUM6.2The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow Li...
CVE-2025-34210MEDIUM5.5Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number o...
CVE-2025-57305MEDIUM6.5VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.
CVE-2025-56162MEDIUM6.5YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint....
CVE-2025-56154MEDIUM6.1htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The ...
CVE-2025-61096MEDIUM6.5PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname pa...
CVE-2025-61087MEDIUM6.1SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name fi...
CVE-2025-60782MEDIUM5.4PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability i...
CVE-2025-59774MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59773MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59772MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59771MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59770MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59769MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now