2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8308MEDIUM6.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Key Softwar...
CVE-2025-8781MEDIUM4.9The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘raw’ pa...
CVE-2025-7630MEDIUM5.3Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication ...
CVE-2025-14799MEDIUM6.5The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type...
CVE-2025-14444MEDIUM5.3The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2025-13727MEDIUM4.4The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-11185MEDIUM6.4The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2025-12356MEDIUM4.3The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2025-12122MEDIUM6.4The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-11737MEDIUM6.4The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns...
CVE-2025-6460MEDIUM6.4The Display During Conditional Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mess...
CVE-2025-13959MEDIUM6.4The Filestack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'filepicker' shortcode ...
CVE-2025-12075MEDIUM4.3The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca...
CVE-2025-12074MEDIUM5.3The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 v...
CVE-2025-12071MEDIUM4.3The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an...
CVE-2025-12037MEDIUM4.4The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin set...
CVE-2025-62183MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-site Scripting vulnerability in a user interf...
CVE-2025-13333MEDIUM4.9IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration o...
CVE-2025-36348MEDIUM4.9IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, an...
CVE-2025-33135MEDIUM6.1IBM Financial Transaction Manager for ACH Services and Check Services for Multi-Platform 3.0.0.0 through 3.0.5.4 Interim...
CVE-2025-14289MEDIUM5.4IBM webMethods Integration Server 12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2025-13691MEDIUM6.5IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be ...
CVE-2025-36598MEDIUM6.5Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di...
CVE-2025-36597MEDIUM4.7Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di...
CVE-2025-36243MEDIUM4.3IBM Concert 1.0.0 through 2.1.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated att...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now