2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-27358MEDIUM4.6Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Man...
CVE-2025-27326MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gal...
CVE-2025-26591MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam WP fancy...
CVE-2025-24764MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones (Simply) ...
CVE-2025-24757MEDIUM5.3Missing Authorization vulnerability in AndonDesign uDesign udesign.This issue affects uDesign: from n/a through <= 4.11....
CVE-2025-24748MEDIUM5.3Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.
CVE-2025-23972MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Brian S. Reed Contact Form 7 reCAPTCHA contact-form-7-recaptcha allow...
CVE-2025-6673MEDIUM6.4The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_...
CVE-2025-6944MEDIUM6.4The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and ...
CVE-2025-7053MEDIUM6.1A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown pro...
CVE-2025-7046MEDIUM5.4The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2025-6787MEDIUM5.4The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartdocs_search' sho...
CVE-2025-6786MEDIUM5.3The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, ...
CVE-2025-6739MEDIUM6.5The WPQuiz plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'wpquiz' shortcode in all v...
CVE-2025-6729MEDIUM6.4The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a...
CVE-2025-6041MEDIUM6.1The yContributors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-6039MEDIUM6.4The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4w...
CVE-2025-5933MEDIUM4.3The RD Contacto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-5924MEDIUM4.3The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2025-5567MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-53370MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, ...
CVE-2025-53368MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, ...
CVE-2025-52554MEDIUM4.3n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /re...
CVE-2025-45809MEDIUM5.4SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key ...
CVE-2025-6074MEDIUM6.5Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enable...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now