2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-50031MEDIUM6.5Missing Authorization vulnerability in syedamirhussain91 DB Backup db-backup allows Exploiting Incorrectly Configured Ac...
CVE-2025-50029MEDIUM6.5Missing Authorization vulnerability in Ashish AI Tools artificial-intelligence-auto-content-generator allows Exploiting ...
CVE-2025-49437MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in worstguy WP LOL Ro...
CVE-2025-49433MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThanhD Supermalink...
CVE-2025-49061MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perteus Porn Video...
CVE-2025-49053MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kadesthemes WP Air...
CVE-2025-49052MEDIUM4.3Missing Authorization vulnerability in Dariolee Netease Music netease-music allows Exploiting Incorrectly Configured Acc...
CVE-2025-49051MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biscia7 Hide Text ...
CVE-2025-49048MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inspectlet Inspect...
CVE-2025-49047MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keeross DigitalOce...
CVE-2025-47610MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wetail WooCommerce...
CVE-2025-39483MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injecti...
CVE-2025-30993MEDIUM6.5Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customize...
CVE-2025-28987MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in PressForward PressForward pressforward allows Server Side Request Fo...
CVE-2025-28962MEDIUM6.5Missing Authorization vulnerability in stefanoai Advanced Google Universal Analytics advanced-google-universal-analytics...
CVE-2025-7761MEDIUM5.1Lepszy BIP is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in index.php form in one of ...
CVE-2025-5998MEDIUM6.5The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a passwor...
CVE-2025-48861MEDIUM5.3A vulnerability in the Task API endpoint of the ctrlX OS setup mechanism allowed a remote, unauthenticated attacker to a...
CVE-2025-8046MEDIUM6.1The Injection Guard WordPress plugin before 1.2.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputtin...
CVE-2025-7808MEDIUM6.1The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2025-6790MEDIUM4.3The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its set...
CVE-2025-3414MEDIUM5.4The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block opti...
CVE-2025-8938MEDIUM6.3A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boa...
CVE-2025-5942MEDIUM5.7Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully ex...
CVE-2025-0309MEDIUM6An insufficient validation on the server connection endpoint in Netskope Client allows local users to elevate privileges...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now