2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53206MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega...
CVE-2025-53203MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder al...
CVE-2025-53202MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon...
CVE-2025-53200MEDIUM4.3Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-53199MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Slid...
CVE-2025-53197MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in cookiebot Cookiebot cookiebot allows Cross Site Request Forgery.This ...
CVE-2025-53193MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Burst Statistics B.V. Burst Statistics burst-statistics allows Cross ...
CVE-2025-52993MEDIUM5.6A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID...
CVE-2025-45729MEDIUM6.3D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet servic...
CVE-2025-44163MEDIUM6.3RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attac...
CVE-2025-6767MEDIUM6.3A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. It has been rated as cr...
CVE-2025-40910MEDIUM6.5Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which ...
CVE-2025-49321MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin ...
CVE-2025-32281MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite darkmysite allows Cross Site Request Forgery.Th...
CVE-2025-5398MEDIUM5.4The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2025-6689MEDIUM5.4The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3racce...
CVE-2025-6550MEDIUM5.4The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options’ ...
CVE-2025-5940MEDIUM5.4The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-5936MEDIUM4.3The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2025-4587MEDIUM6.4The A/B Testing for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ab-tes...
CVE-2025-5526MEDIUM4.3The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and d...
CVE-2025-5194MEDIUM4.8The WP Map Block WordPress plugin before 2.0.3 does not validate and escape some of its block options before outputting...
CVE-2025-5093MEDIUM5.4The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and esc...
CVE-2025-5035MEDIUM5.4The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting th...
CVE-2025-41418MEDIUM6.9Buffer Overflow vulnerability exists in multiple versions of TB-eye network recorders and AHD recorders. The CGI process...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now