2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8776MEDIUM6.4The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ parameter in...
CVE-2025-8669MEDIUM4.3The Customify theme for WordPress is vulnerable to Cross-Site Request Forgery in version 0.4.11. This is due to missing ...
CVE-2025-7825MEDIUM6.3The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all ver...
CVE-2025-49641MEDIUM4.3A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refre...
CVE-2025-27236MEDIUM6.5A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have ...
CVE-2025-27231MEDIUM4.9The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host...
CVE-2025-10311MEDIUM4.3The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-10309MEDIUM4.3The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-10302MEDIUM4.3The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2025-10212MEDIUM5.3The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca...
CVE-2025-10192MEDIUM6.4The WP Photo Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wppe_effect' sh...
CVE-2025-10165MEDIUM6.4The AP Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adv_parallax_back'...
CVE-2025-10053MEDIUM4.4The TableGen – Data Table Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings...
CVE-2025-0876MEDIUM4.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Isin Basi A...
CVE-2025-61599MEDIUM5.4Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitte...
CVE-2025-61597MEDIUM5.4Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored ...
CVE-2025-61589MEDIUM5.9Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows ...
CVE-2025-11241MEDIUM6.4The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to ...
CVE-2025-61606MEDIUM6.1WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open R...
CVE-2025-54088MEDIUM6.1CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the c...
CVE-2025-56019MEDIUM6.5An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobil...
CVE-2025-60661MEDIUM5.3Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWa...
CVE-2025-59406MEDIUM6.2The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow Li...
CVE-2025-34210MEDIUM5.5Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number o...
CVE-2025-57305MEDIUM6.5VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now