2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6382 | MEDIUM | 6.4 | 0.4% | Jul 24, 2025 | The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's taeggie-feed shortco... |
| CVE-2025-6262 | MEDIUM | 6.4 | 0.4% | Jul 24, 2025 | The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai s... |
| CVE-2025-5084 | MEDIUM | 6.1 | 0.5% | Jul 24, 2025 | The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_... |
| CVE-2025-4608 | MEDIUM | 6.4 | 0.4% | Jul 24, 2025 | The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_bu... |
| CVE-2025-3669 | MEDIUM | 6.4 | 0.4% | Jul 24, 2025 | The Supreme Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2025-8107 | MEDIUM | 6.3 | 0.3% | Jul 24, 2025 | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-lev... |
| CVE-2025-8009 | MEDIUM | 4.9 | 0.6% | Jul 24, 2025 | The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in a... |
| CVE-2025-7745 | MEDIUM | 6.9 | 0.4% | Jul 24, 2025 | Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2. |
| CVE-2025-4976 | MEDIUM | 5.3 | 0.4% | Jul 24, 2025 | An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 b... |
| CVE-2025-4968 | MEDIUM | 5.4 | 0.3% | Jul 24, 2025 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple P... |
| CVE-2025-4395 | MEDIUM | 6.8 | 0.3% | Jul 24, 2025 | Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with p... |
| CVE-2025-4394 | MEDIUM | 6.8 | 0.2% | Jul 24, 2025 | Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with p... |
| CVE-2025-4393 | MEDIUM | 6.5 | 0.2% | Jul 24, 2025 | Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to in... |
| CVE-2025-1299 | MEDIUM | 4.3 | 0.3% | Jul 24, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions start... |
| CVE-2025-0765 | MEDIUM | 4.3 | 0.4% | Jul 24, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.... |
| CVE-2025-32019 | MEDIUM | 4.1 | 0.3% | Jul 23, 2025 | Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 an... |
| CVE-2025-8058 | MEDIUM | 5.9 | 0.2% | Jul 23, 2025 | The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocat... |
| CVE-2025-44109 | MEDIUM | 5.4 | 0.2% | Jul 23, 2025 | A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages. |
| CVE-2025-50477 | MEDIUM | 5.4 | 0.3% | Jul 23, 2025 | A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages. |
| CVE-2025-4700 | MEDIUM | 6.1 | 0.2% | Jul 23, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18... |
| CVE-2025-4439 | MEDIUM | 5.4 | 0.2% | Jul 23, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18... |
| CVE-2025-50481 | MEDIUM | 4.8 | 0.6% | Jul 23, 2025 | A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers ... |
| CVE-2025-46171 | MEDIUM | 5.4 | 0.3% | Jul 23, 2025 | vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticat... |
| CVE-2025-40598 | MEDIUM | 6.1 | 53.2% | Jul 23, 2025 | A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauth... |
| CVE-2025-36117 | MEDIUM | 6.3 | 0.2% | Jul 23, 2025 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated use... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now