2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10759MEDIUM5.5A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token...
CVE-2025-10758MEDIUM4.8A security vulnerability has been detected in htmly up to 3.1.0. The impacted element is an unknown function of the file...
CVE-2025-10755MEDIUM6.3A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component...
CVE-2025-10741MEDIUM6.3A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown funct...
CVE-2025-9887MEDIUM4.3The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-9883MEDIUM6.1The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-9882MEDIUM6.1The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-10658MEDIUM6.5The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass...
CVE-2025-9949MEDIUM4.3The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-10489MEDIUM4.3The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPres...
CVE-2025-10305MEDIUM5.3The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the d...
CVE-2025-10181MEDIUM6.4The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in ...
CVE-2025-10002MEDIUM4.9The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is...
CVE-2025-10652MEDIUM6.5The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore-net...
CVE-2025-43808MEDIUM5.3The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1...
CVE-2025-9081MEDIUM6.5Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authe...
CVE-2025-59689MEDIUM6.1Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a ...
CVE-2025-57396MEDIUM6.5Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework ...
CVE-2025-56762MEDIUM6.1Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.
CVE-2025-43809MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 throug...
CVE-2025-43803MEDIUM4.3Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4....
CVE-2025-26517MEDIUM5.4StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a privilege es...
CVE-2025-26516MEDIUM5.3StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Se...
CVE-2025-26514MEDIUM6.4StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cr...
CVE-2025-10722MEDIUM5.3A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file Andr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now