2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-52460MEDIUM6.9Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a...
CVE-2025-8073MEDIUM6.4The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-6255MEDIUM6.4The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-7956MEDIUM5.3The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in it...
CVE-2025-8977MEDIUM6.5The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in al...
CVE-2025-9346MEDIUM6.4The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up t...
CVE-2025-9345MEDIUM4.9The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versio...
CVE-2025-8603MEDIUM6.4The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widge...
CVE-2025-0951MEDIUM4.3Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capa...
CVE-2025-9352MEDIUM5.4The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in ...
CVE-2025-9344MEDIUM6.4The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2025-8897MEDIUM6.1The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
CVE-2025-36003MEDIUM5.3IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information whe...
CVE-2025-34521MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection...
CVE-2025-5101MEDIUM5An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1...
CVE-2025-55582MEDIUM6.6D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly ...
CVE-2025-3601MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18....
CVE-2025-2246MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1...
CVE-2025-55495MEDIUM6.5Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind ...
CVE-2025-58216MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP Thumb...
CVE-2025-58213MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ameliabooking Book...
CVE-2025-58212MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in epeken Epeken All ...
CVE-2025-58211MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alexvtn Chatbox Ma...
CVE-2025-58209MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtCamp Transcoder ...
CVE-2025-58208MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF fo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now