2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53206 | MEDIUM | 6.5 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega... |
| CVE-2025-53203 | MEDIUM | 4.3 | 0.1% | Jun 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder al... |
| CVE-2025-53202 | MEDIUM | 6.5 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon... |
| CVE-2025-53200 | MEDIUM | 4.3 | 0.2% | Jun 27, 2025 | Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-53199 | MEDIUM | 6.5 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Slid... |
| CVE-2025-53197 | MEDIUM | 4.3 | 0.1% | Jun 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in cookiebot Cookiebot cookiebot allows Cross Site Request Forgery.This ... |
| CVE-2025-53193 | MEDIUM | 4.3 | 0.1% | Jun 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Burst Statistics B.V. Burst Statistics burst-statistics allows Cross ... |
| CVE-2025-52993 | MEDIUM | 5.6 | 0.1% | Jun 27, 2025 | A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID... |
| CVE-2025-45729 | MEDIUM | 6.3 | 0.3% | Jun 27, 2025 | D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet servic... |
| CVE-2025-44163 | MEDIUM | 6.3 | 0.6% | Jun 27, 2025 | RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attac... |
| CVE-2025-6767 | MEDIUM | 6.3 | 0.2% | Jun 27, 2025 | A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. It has been rated as cr... |
| CVE-2025-40910 | MEDIUM | 6.5 | 0.3% | Jun 27, 2025 | Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which ... |
| CVE-2025-49321 | MEDIUM | 6.1 | 0.2% | Jun 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arraytics Eventin ... |
| CVE-2025-32281 | MEDIUM | 4.3 | 0.1% | Jun 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite darkmysite allows Cross Site Request Forgery.Th... |
| CVE-2025-5398 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2025-6689 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3racce... |
| CVE-2025-6550 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options’ ... |
| CVE-2025-5940 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-5936 | MEDIUM | 4.3 | 0.1% | Jun 27, 2025 | The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2025-4587 | MEDIUM | 6.4 | 0.2% | Jun 27, 2025 | The A/B Testing for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ab-tes... |
| CVE-2025-5526 | MEDIUM | 4.3 | 0.2% | Jun 27, 2025 | The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and d... |
| CVE-2025-5194 | MEDIUM | 4.8 | 0.2% | Jun 27, 2025 | The WP Map Block WordPress plugin before 2.0.3 does not validate and escape some of its block options before outputting... |
| CVE-2025-5093 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and esc... |
| CVE-2025-5035 | MEDIUM | 5.4 | 0.2% | Jun 27, 2025 | The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting th... |
| CVE-2025-41418 | MEDIUM | 6.9 | 0.3% | Jun 27, 2025 | Buffer Overflow vulnerability exists in multiple versions of TB-eye network recorders and AHD recorders. The CGI process... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now