2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27358 | MEDIUM | 4.6 | 0.2% | Jul 4, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Man... |
| CVE-2025-27326 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gal... |
| CVE-2025-26591 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam WP fancy... |
| CVE-2025-24764 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones (Simply) ... |
| CVE-2025-24757 | MEDIUM | 5.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in AndonDesign uDesign udesign.This issue affects uDesign: from n/a through <= 4.11.... |
| CVE-2025-24748 | MEDIUM | 5.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10. |
| CVE-2025-23972 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Brian S. Reed Contact Form 7 reCAPTCHA contact-form-7-recaptcha allow... |
| CVE-2025-6673 | MEDIUM | 6.4 | 0.2% | Jul 4, 2025 | The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_... |
| CVE-2025-6944 | MEDIUM | 6.4 | 0.2% | Jul 4, 2025 | The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and ... |
| CVE-2025-7053 | MEDIUM | 6.1 | 0.3% | Jul 4, 2025 | A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown pro... |
| CVE-2025-7046 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2025-6787 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartdocs_search' sho... |
| CVE-2025-6786 | MEDIUM | 5.3 | 0.3% | Jul 4, 2025 | The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, ... |
| CVE-2025-6739 | MEDIUM | 6.5 | 0.3% | Jul 4, 2025 | The WPQuiz plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'wpquiz' shortcode in all v... |
| CVE-2025-6729 | MEDIUM | 6.4 | 0.2% | Jul 4, 2025 | The PayMaster for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a... |
| CVE-2025-6041 | MEDIUM | 6.1 | 0.1% | Jul 4, 2025 | The yContributors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-6039 | MEDIUM | 6.4 | 0.2% | Jul 4, 2025 | The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4w... |
| CVE-2025-5933 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | The RD Contacto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-5924 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2025-5567 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-53370 | MEDIUM | 5.4 | 0.3% | Jul 3, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, ... |
| CVE-2025-53368 | MEDIUM | 5.4 | 0.3% | Jul 3, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, ... |
| CVE-2025-52554 | MEDIUM | 4.3 | 0.3% | Jul 3, 2025 | n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /re... |
| CVE-2025-45809 | MEDIUM | 5.4 | 0.3% | Jul 3, 2025 | SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key ... |
| CVE-2025-6074 | MEDIUM | 6.5 | 0.2% | Jul 3, 2025 | Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enable... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now