2025 CVE Vulnerabilities

45,345 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8208MEDIUM6.4The Spexo Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countd...
CVE-2025-9131MEDIUM6.4The Ogulo – 360° Tour plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter in all ...
CVE-2025-8062MEDIUM6.4The WS Theme Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ws_weather shortc...
CVE-2025-7957MEDIUM6.4The ShortcodeHub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_link_target’ paramete...
CVE-2025-7842MEDIUM4.3The Silencesoft RSS Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-7841MEDIUM4.3The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Reque...
CVE-2025-7839MEDIUM4.3The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-7828MEDIUM4.3The WP Filter & Combine RSS Feeds plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2025-7827MEDIUM4.3The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2025-7821MEDIUM5.3The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2025-43765MEDIUM6.1A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 20...
CVE-2025-43764MEDIUM6.5Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScrip...
CVE-2025-43767MEDIUM6.1Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131,...
CVE-2025-43769MEDIUM6.1Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 thr...
CVE-2025-43770MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024...
CVE-2025-52450MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Serve...
CVE-2025-43761MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024...
CVE-2025-54812MEDIUM5.4Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not p...
CVE-2025-50859MEDIUM6.1Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows aut...
CVE-2025-50858MEDIUM6.1Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allow...
CVE-2025-43762MEDIUM6.5Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-43758MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-43760MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-57770MEDIUM5.3The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Ve...
CVE-2025-55631MEDIUM4Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage use...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now