2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8508MEDIUM5.4A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerabilit...
CVE-2025-8507MEDIUM5.4A vulnerability was found in Portabilis i-Educar 2.9. It has been classified as problematic. Affected is an unknown func...
CVE-2025-8505MEDIUM4.3A vulnerability has been found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as pro...
CVE-2025-8501MEDIUM5.4A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected...
CVE-2025-52133MEDIUM6.4The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.
CVE-2025-52132MEDIUM6.4The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.
CVE-2025-52131MEDIUM6.4The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.
CVE-2025-54350MEDIUM5.3In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authenti...
CVE-2025-23285MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resou...
CVE-2025-23286MEDIUM4.4NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A ...
CVE-2025-7500MEDIUM6.4The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all...
CVE-2025-8488MEDIUM4.3The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to una...
CVE-2025-6722MEDIUM5.3The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive I...
CVE-2025-8400MEDIUM6.1The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ...
CVE-2025-8399MEDIUM6.4The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in...
CVE-2025-8391MEDIUM6.4The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in al...
CVE-2025-6832MEDIUM6.1The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Refl...
CVE-2025-8317MEDIUM6.4The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all...
CVE-2025-8212MEDIUM6.4The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typew...
CVE-2025-8152MEDIUM5.3The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modifi...
CVE-2025-6626MEDIUM4.4The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-...
CVE-2025-4588MEDIUM6.4The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortc...
CVE-2025-8146MEDIUM6.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut T...
CVE-2025-6078MEDIUM5.4Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on...
CVE-2025-54790MEDIUM6.5Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now