2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8113MEDIUM6.1The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting i...
CVE-2025-8293MEDIUM6.4The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in...
CVE-2025-7686MEDIUM6.1The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2025-7684MEDIUM6.1The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-7683MEDIUM6.1The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-7668MEDIUM6.1The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2025-7651MEDIUM6.4The Earnware Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ew_hasrole' sho...
CVE-2025-7649MEDIUM6.4The Surbma | Recent Comments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2025-7440MEDIUM6.4The Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $item['button_link']...
CVE-2025-7439MEDIUM6.4Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $anber_item['button_link...
CVE-2025-6221MEDIUM6.4The Embed Bokun plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versi...
CVE-2025-49895MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This i...
CVE-2025-52620MEDIUM5.4HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload func...
CVE-2025-52619MEDIUM5.3HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, err...
CVE-2025-43201MEDIUM6.2This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may ...
CVE-2025-36088MEDIUM5.4IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This...
CVE-2025-8996MEDIUM4.3Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue af...
CVE-2025-8362MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag M...
CVE-2025-7961MEDIUM6.9Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS allows TCC Bypass.This i...
CVE-2025-8066MEDIUM4.8URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bunkerity Bunker Web on Linux allows Phishing.This ...
CVE-2025-55207MEDIUM5.5Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerabil...
CVE-2025-49432MEDIUM5.3Missing Authorization vulnerability in FWDesign Ultimate Video Player fwduvp allows Exploiting Incorrectly Configured Ac...
CVE-2025-55203MEDIUM5.4Plane is open-source project management software. Prior to version 0.28.0, a stored cross-site scripting (XSS) vulnerabi...
CVE-2025-26709MEDIUM5.7There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface...
CVE-2025-8905MEDIUM6.3The Inpersttion For Theme plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now