2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6986MEDIUM6.5The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via th...
CVE-2025-6690MEDIUM6.4The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ paramet...
CVE-2025-6259MEDIUM6.4The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view short...
CVE-2025-6256MEDIUM6.4The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ paramete...
CVE-2025-54623MEDIUM6.5Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-54620MEDIUM5.5Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerabi...
CVE-2025-54618MEDIUM5.7Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerabil...
CVE-2025-54616MEDIUM5.5Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability m...
CVE-2025-54615MEDIUM5.5Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of thi...
CVE-2025-54614MEDIUM5.5Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may af...
CVE-2025-54611MEDIUM5.5EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability ...
CVE-2025-54608MEDIUM4Vulnerability that allows setting screen rotation direction without permission verification in the screen management mod...
CVE-2025-54653MEDIUM6.5Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect...
CVE-2025-54652MEDIUM5.5Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect...
CVE-2025-54876MEDIUM6.9The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Jansse...
CVE-2025-54869MEDIUM6FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template...
CVE-2025-54571MEDIUM6.1ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versio...
CVE-2025-54125MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ...
CVE-2025-54124MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ...
CVE-2025-32430MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2...
CVE-2025-8573MEDIUM4.8Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.  Version ...
CVE-2025-8571MEDIUM4.8Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversa...
CVE-2025-52237MEDIUM6.5An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory travers...
CVE-2025-52078MEDIUM6.5File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to ...
CVE-2025-51541MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/d...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now