2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-60099MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Embed Any ...
CVE-2025-60098MEDIUM6.5Missing Authorization vulnerability in Jeff Farthing Theme My Login theme-my-login allows Exploiting Incorrectly Configu...
CVE-2025-60097MEDIUM5.4Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control...
CVE-2025-60096MEDIUM5.4Missing Authorization vulnerability in CodexThemes TheGem (Elementor) thegem-elementor allows Exploiting Incorrectly Con...
CVE-2025-60095MEDIUM4.3Insertion of Sensitive Information Into Sent Data vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg...
CVE-2025-60094MEDIUM4.3Missing Authorization vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Exploiting In...
CVE-2025-60093MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager download-manager allows Cross Site Request ...
CVE-2025-60092MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager do...
CVE-2025-60040MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fkrauthan wp-mpdf ...
CVE-2025-58919MEDIUM5.3Missing Authorization vulnerability in guihom Wide Banner wide-banner allows Exploiting Incorrectly Configured Access Co...
CVE-2025-58917MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Verwymeren Qu...
CVE-2025-58914MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Di Themes Di Themes Demo Site Importer di-themes-demo-site-importer a...
CVE-2025-48326MEDIUM6.5Missing Authorization vulnerability in Acclectic Media Acclectic Media Organizer acclectic-media-organizer allows Exploi...
CVE-2025-27006MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeplugs Authors...
CVE-2025-10867MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18....
CVE-2025-54831MEDIUM6.5Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict...
CVE-2025-1396MEDIUM5.3A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this con...
CVE-2025-10490MEDIUM4.4The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...
CVE-2025-10307MEDIUM6.5The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to i...
CVE-2025-10180MEDIUM6.4The Markdown Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'markdown' sho...
CVE-2025-10137MEDIUM5.4The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2...
CVE-2025-10136MEDIUM6.4The TweetThis Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tweetthis' s...
CVE-2025-9490MEDIUM6.4The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versi...
CVE-2025-9985MEDIUM5.3The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2025-9984MEDIUM5.3The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now