2025 CVE Vulnerabilities

45,173 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-50057MEDIUM6.9A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote a...
CVE-2025-50056MEDIUM5.1A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote a...
CVE-2025-2425MEDIUM5.1Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET secu...
CVE-2025-6226MEDIUM6.5Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization...
CVE-2025-6197MEDIUM4.2An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites ...
CVE-2025-7772MEDIUM6.5The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F...
CVE-2025-6726MEDIUM4.3The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2025-6719MEDIUM4.4The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2025-6717MEDIUM6.5The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and includin...
CVE-2025-5811MEDIUM5.3The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-5800MEDIUM6.4The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ paramete...
CVE-2025-5767MEDIUM6.4The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ param...
CVE-2025-5754MEDIUM6.4The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2025-5752MEDIUM6.4The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘w...
CVE-2025-7660MEDIUM6.4The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_location...
CVE-2025-7648MEDIUM6.4The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_b...
CVE-2025-7638MEDIUM4.9The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based...
CVE-2025-6781MEDIUM4.3The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve...
CVE-2025-6053MEDIUM6.1The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2025-5816MEDIUM4.3The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure...
CVE-2025-7431MEDIUM4.4The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all ...
CVE-2025-7767MEDIUM5.4A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Af...
CVE-2025-7763MEDIUM4.3A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the functi...
CVE-2025-7762MEDIUM6.5A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some ...
CVE-2025-7756MEDIUM4.3A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown fu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now