2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8266MEDIUM6.3A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerab...
CVE-2025-8265MEDIUM4.7A vulnerability classified as critical has been found in 299Ko CMS 2.0.0. This affects an unknown part of the file /admi...
CVE-2025-27802MEDIUM4.8The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) v...
CVE-2025-27801MEDIUM4.8The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) v...
CVE-2025-27800MEDIUM4.8The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) v...
CVE-2025-8267MEDIUM5.3Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete...
CVE-2025-8258MEDIUM5.3A vulnerability, which was classified as problematic, has been found in Cool Mo Maigcal Number App up to 1.0.3 on Androi...
CVE-2025-8257MEDIUM5.3A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this...
CVE-2025-8231MEDIUM6.8A vulnerability, which was classified as critical, has been found in D-Link DIR-890L up to 111b04. This issue affects so...
CVE-2025-8224MEDIUM5.5A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the functi...
CVE-2025-8223MEDIUM4.3A vulnerability, which was classified as problematic, was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f...
CVE-2025-8222MEDIUM5.4A vulnerability, which was classified as problematic, has been found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c...
CVE-2025-8221MEDIUM6.1A vulnerability classified as problematic was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f61...
CVE-2025-8104MEDIUM4.3The Memory Usage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-54597MEDIUM6.1LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
CVE-2025-6241MEDIUM4.4LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present i...
CVE-2025-8211MEDIUM6.1A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is t...
CVE-2025-8210MEDIUM4.4A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affecte...
CVE-2025-8207MEDIUM4.4A vulnerability was found in Canara ai1 Mobile Banking App 3.6.23 on Android and classified as problematic. This issue a...
CVE-2025-8206MEDIUM4.7A vulnerability, which was classified as problematic, was found in Comodo Dragon up to 134.0.6998.179. This affects an u...
CVE-2025-8191MEDIUM5.4A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown f...
CVE-2025-5529MEDIUM6.4The Educenter theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Circle Counter Block in all versi...
CVE-2025-8097MEDIUM5.3The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6....
CVE-2025-7501MEDIUM6.4The Wonder Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image title and description...
CVE-2025-6987MEDIUM6.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now