2025 CVE Vulnerabilities

45,169 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58797MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Mahmudul Hasan Arif Ninja Ch...
CVE-2025-58796MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dudaster Elementor...
CVE-2025-58795MEDIUM4.3Missing Authorization vulnerability in Payoneer Checkout Payoneer Checkout payoneer-checkout allows Content Spoofing.Thi...
CVE-2025-58794MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in rainafarai Notification for Telegram notification-for-telegram allows...
CVE-2025-58793MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Element...
CVE-2025-58792MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List authors-list allows Cross Site Request Forgery.Th...
CVE-2025-58791MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arjan Olsder SEO A...
CVE-2025-58790MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Kiwi kiwi-s...
CVE-2025-58787MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify ...
CVE-2025-58786MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana –...
CVE-2025-58785MEDIUM5.4Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting I...
CVE-2025-58784MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft ARI Fancy ...
CVE-2025-58783MEDIUM4.3Missing Authorization vulnerability in gutentor Gutentor gutentor allows Exploiting Incorrectly Configured Access Contro...
CVE-2025-58296MEDIUM4.7Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect funct...
CVE-2025-58281MEDIUM5.5Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation of this vulnerabilit...
CVE-2025-58280MEDIUM5.5Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitation of this vulnerabi...
CVE-2025-58276MEDIUM5.5Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability ma...
CVE-2025-48395MEDIUM4.7An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the...
CVE-2025-8944MEDIUM4.3The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of i...
CVE-2025-41408MEDIUM5.3Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14....
CVE-2025-58401MEDIUM6.8Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacke...
CVE-2025-8684MEDIUM6.4The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions...
CVE-2025-7445MEDIUM6.5Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.
CVE-2025-58359MEDIUM6ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 th...
CVE-2025-58352MEDIUM6.5Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session ex...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now