2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2425MEDIUM5.1Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET secu...
CVE-2025-6226MEDIUM6.5Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization...
CVE-2025-6197MEDIUM4.2An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites ...
CVE-2025-7772MEDIUM6.5The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F...
CVE-2025-6726MEDIUM4.3The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2025-6719MEDIUM4.4The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2025-6717MEDIUM6.5The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and includin...
CVE-2025-5811MEDIUM5.3The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-5800MEDIUM6.4The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ paramete...
CVE-2025-5767MEDIUM6.4The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ param...
CVE-2025-5754MEDIUM6.4The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2025-5752MEDIUM6.4The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘w...
CVE-2025-7660MEDIUM6.4The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_location...
CVE-2025-7648MEDIUM6.4The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_b...
CVE-2025-7638MEDIUM4.9The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based...
CVE-2025-6781MEDIUM4.3The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve...
CVE-2025-6053MEDIUM6.1The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2025-5816MEDIUM4.3The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure...
CVE-2025-7431MEDIUM4.4The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all ...
CVE-2025-7767MEDIUM5.4A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Af...
CVE-2025-7763MEDIUM4.3A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the functi...
CVE-2025-7762MEDIUM6.5A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some ...
CVE-2025-7756MEDIUM4.3A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown fu...
CVE-2025-23269MEDIUM4.7NVIDIA Jetson Linux contains a vulnerability in the kernel where an attacker may cause an exposure of sensitive informat...
CVE-2025-6230MEDIUM5.3A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now