2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9215MEDIUM6.5The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor...
CVE-2025-9203MEDIUM6.4The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitl...
CVE-2025-9818MEDIUM6.7A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided ...
CVE-2025-55075MEDIUM6.9Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled ...
CVE-2025-10584MEDIUM5.4A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/...
CVE-2025-10188MEDIUM5.4The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio...
CVE-2025-10125MEDIUM6.4The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shor...
CVE-2025-9891MEDIUM4.3The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-9851MEDIUM6.4The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar...
CVE-2025-9629MEDIUM4.3The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5...
CVE-2025-8394MEDIUM6.4The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_producti...
CVE-2025-8153MEDIUM5.1Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8...
CVE-2025-10166MEDIUM6.4The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twitter'...
CVE-2025-10050MEDIUM6.6The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up t...
CVE-2025-43804MEDIUM6.1Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP ...
CVE-2025-37131MEDIUM4.9A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to acc...
CVE-2025-37130MEDIUM6.5A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitr...
CVE-2025-37129MEDIUM6.7A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploi...
CVE-2025-37128MEDIUM6.8A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote a...
CVE-2025-9708MEDIUM6.8A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed c...
CVE-2025-43805MEDIUM5.3Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92...
CVE-2025-10566MEDIUM6.1A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unkno...
CVE-2025-49728MEDIUM4Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security ...
CVE-2025-47967MEDIUM4.7Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform...
CVE-2025-54237MEDIUM5.5Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now