2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54831MEDIUM6.5Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict...
CVE-2025-1396MEDIUM5.3A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this con...
CVE-2025-10490MEDIUM4.4The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...
CVE-2025-10307MEDIUM6.5The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to i...
CVE-2025-10180MEDIUM6.4The Markdown Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'markdown' sho...
CVE-2025-10137MEDIUM5.4The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2...
CVE-2025-10136MEDIUM6.4The TweetThis Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tweetthis' s...
CVE-2025-9490MEDIUM6.4The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versi...
CVE-2025-9985MEDIUM5.3The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2025-9984MEDIUM5.3The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca...
CVE-2025-10037MEDIUM4.9The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_f...
CVE-2025-10036MEDIUM4.9The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_all_urls() function i...
CVE-2025-9044MEDIUM6.4The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple fields in versions up...
CVE-2025-11000MEDIUM5.5A vulnerability was determined in Open Babel up to 3.1.1. This affects the function PQSFormat::ReadMolecule of the file ...
CVE-2025-10745MEDIUM5.3The Banhammer – Monitor Site Traffic, Block Bad Users and Bots plugin for WordPress is vulnerable to Blocking Bypass in ...
CVE-2025-10377MEDIUM4.3The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-10999MEDIUM5.5A vulnerability was found in Open Babel up to 3.1.1. The impacted element is the function CacaoFormat::SetHilderbrandt o...
CVE-2025-10998MEDIUM5.5A vulnerability has been found in Open Babel up to 3.1.1. The affected element is the function ChemKinFormat::ReadReacti...
CVE-2025-8906MEDIUM6.4The Widgets for Tiktok Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trustind...
CVE-2025-8200MEDIUM6.4The Mega Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2025-10992MEDIUM5.5A vulnerability was determined in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. Affected is an unkno...
CVE-2025-10752MEDIUM4.3The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve...
CVE-2025-10178MEDIUM6.4The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featu...
CVE-2025-60251MEDIUM5Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.
CVE-2025-60250MEDIUM4.7Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now