2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9979MEDIUM4.3The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missin...
CVE-2025-9888MEDIUM4.3The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2025-9857MEDIUM6.4The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2025-9622MEDIUM4.3The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-9463MEDIUM6.5The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v...
CVE-2025-9367MEDIUM5.5The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up...
CVE-2025-8778MEDIUM4.3The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2025-7843MEDIUM6.4The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u...
CVE-2025-7826MEDIUM6.5The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions ...
CVE-2025-6189MEDIUM6.5The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter ...
CVE-2025-10142MEDIUM4.9The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' pa...
CVE-2025-10126MEDIUM6.4The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' short...
CVE-2025-8388MEDIUM6.4The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cro...
CVE-2025-10197MEDIUM6.3A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability...
CVE-2025-10195MEDIUM5.3A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManif...
CVE-2025-59044MEDIUM4.4Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs f...
CVE-2025-9997MEDIUM5.8CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2025-59036MEDIUM5.5Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the ...
CVE-2025-58135MEDIUM6.5Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a...
CVE-2025-58134MEDIUM4.3Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impa...
CVE-2025-58131MEDIUM6.6Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or b...
CVE-2025-49458MEDIUM6.5Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via net...
CVE-2025-9996MEDIUM5.8CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2025-7746MEDIUM5.3CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that c...
CVE-2025-54241MEDIUM5.5After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now