2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8720MEDIUM6.4The Plugin README Parser plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘target’ parameter in...
CVE-2025-8091MEDIUM4.3The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4....
CVE-2025-8080MEDIUM4.4The Alobaidi Captcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all ve...
CVE-2025-7688MEDIUM6.1The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-7662MEDIUM6.5The Gestion de tarifs plugin for WordPress is vulnerable to SQL Injection via the 'tarif' and 'intitule' shortcodes in a...
CVE-2025-7507MEDIUM6.4The elink – Embed Content plugin for WordPress is vulnerable to Malicious Redirect in all versions up to, and including,...
CVE-2025-5844MEDIUM6.4The Radius Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subHeadingTagName’ paramete...
CVE-2025-9020MEDIUM4.5A vulnerability was found in PX4 PX4-Autopilot up to 1.15.4. This issue affects the function MavlinkReceiver::handle_mes...
CVE-2025-8604MEDIUM6.4The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2025-9019MEDIUM5.9A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c...
CVE-2025-9017MEDIUM6.1A vulnerability has been found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the f...
CVE-2025-8451MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Bas...
CVE-2025-31961MEDIUM4.6HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai...
CVE-2025-9003MEDIUM5.4A vulnerability has been found in D-Link DIR-818LW 1.04. This vulnerability affects unknown code of the file /bsc_lan.ph...
CVE-2025-8867MEDIUM6.4The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multipl...
CVE-2025-8680MEDIUM4.3The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side Request Forgery in version...
CVE-2025-8676MEDIUM4.3The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in vers...
CVE-2025-8992MEDIUM6.5A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The man...
CVE-2025-8991MEDIUM4.3A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown function...
CVE-2025-8980MEDIUM6.6A vulnerability has been found in Tenda G1 16.01.7.8(3660). Affected by this issue is the function check_upload_file of ...
CVE-2025-8979MEDIUM6.6A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the function check_fw_type/s...
CVE-2025-51965MEDIUM6.1OURPHP thru 8.6.1 is vulnerable to Cross-Site Scripting (XSS) via the "Name" field of the "Complete Profile" functionali...
CVE-2025-50862MEDIUM5.9The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data e...
CVE-2025-50861MEDIUM6.5The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, whi...
CVE-2025-8976MEDIUM5.4A vulnerability has been found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin1...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now