2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6382MEDIUM6.4The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's taeggie-feed shortco...
CVE-2025-6262MEDIUM6.4The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai s...
CVE-2025-5084MEDIUM6.1The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_...
CVE-2025-4608MEDIUM6.4The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_bu...
CVE-2025-3669MEDIUM6.4The Supreme Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2025-8107MEDIUM6.3In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-lev...
CVE-2025-8009MEDIUM4.9The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in a...
CVE-2025-7745MEDIUM6.9Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.
CVE-2025-4976MEDIUM5.3An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 b...
CVE-2025-4968MEDIUM5.4The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple P...
CVE-2025-4395MEDIUM6.8Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with p...
CVE-2025-4394MEDIUM6.8Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with p...
CVE-2025-4393MEDIUM6.5Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to in...
CVE-2025-1299MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions start...
CVE-2025-0765MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18....
CVE-2025-32019MEDIUM4.1Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 an...
CVE-2025-8058MEDIUM5.9The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocat...
CVE-2025-44109MEDIUM5.4A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.
CVE-2025-50477MEDIUM5.4A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.
CVE-2025-4700MEDIUM6.1An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18...
CVE-2025-4439MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18...
CVE-2025-50481MEDIUM4.8A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers ...
CVE-2025-46171MEDIUM5.4vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticat...
CVE-2025-40598MEDIUM6.1A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauth...
CVE-2025-36117MEDIUM6.3IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated use...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now