2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-50128MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVide...
CVE-2025-47061MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46996MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46993MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46410MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality o...
CVE-2025-8114MEDIUM4.7A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key e...
CVE-2025-51089MEDIUM6.5Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of th...
CVE-2025-51088MEDIUM5.3Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argu...
CVE-2025-51085MEDIUM5.3Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the arg...
CVE-2025-51082MEDIUM5.3Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of...
CVE-2025-36005MEDIUM6.5IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ...
CVE-2025-33013MEDIUM5.5IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ...
CVE-2025-45731MEDIUM6.5A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is delet...
CVE-2025-40680MEDIUM6.9Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and ...
CVE-2025-8071MEDIUM6.4Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all version...
CVE-2025-7966MEDIUM6.4The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', and ...
CVE-2025-7959MEDIUM6.4The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter...
CVE-2025-7835MEDIUM4.3The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-7822MEDIUM4.3The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2025-7780MEDIUM6.5The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2025-7690MEDIUM6.1The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-6588MEDIUM6.1The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all ...
CVE-2025-6539MEDIUM6.4The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all ...
CVE-2025-6387MEDIUM6.4The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all ve...
CVE-2025-6385MEDIUM6.4The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now