2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-34141MEDIUM5.1A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverte...
CVE-2025-4284MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rolantis In...
CVE-2025-7900MEDIUM6.5The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of user...
CVE-2025-7899MEDIUM6The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from ...
CVE-2025-7687MEDIUM6.1The Latest Post Accordian Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-7685MEDIUM6.1The Like & Share My Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-7427MEDIUM5.9Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking ...
CVE-2025-6082MEDIUM5.3The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and incl...
CVE-2025-46267MEDIUM6.9Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may ...
CVE-2025-7644MEDIUM6.4The Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio ...
CVE-2025-7495MEDIUM6.4The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpm...
CVE-2025-7953MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS up to 5.202506.a. This issue a...
CVE-2025-7951MEDIUM5.4A vulnerability classified as problematic has been found in code-projects Public Chat Room 1.0. This affects an unknown ...
CVE-2025-7949MEDIUM6.1A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this v...
CVE-2025-6831MEDIUM6.4The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict s...
CVE-2025-5240MEDIUM6.4The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ pa...
CVE-2025-7948MEDIUM6.5A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown fu...
CVE-2025-7946MEDIUM6.1A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as problematic. This...
CVE-2025-7944MEDIUM6.1A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0. It has been classified as problematic. This af...
CVE-2025-7943MEDIUM6.1A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this...
CVE-2025-7486MEDIUM4.4The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Order Details in all versions ...
CVE-2025-7942MEDIUM5.4A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by...
CVE-2025-7941MEDIUM5.4A vulnerability, which was classified as problematic, was found in PHPGurukul Time Table Generator System 1.0. Affected ...
CVE-2025-7940MEDIUM5.3A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affecte...
CVE-2025-54134MEDIUM6.5HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now