2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48497MEDIUM5.1Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a speci...
CVE-2025-41404MEDIUM5.3Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is e...
CVE-2025-3279MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18...
CVE-2025-1754MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18...
CVE-2025-6546MEDIUM5.4The Drive Folder Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tablecssclass’ para...
CVE-2025-6540MEDIUM6.4The web-cam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter in all versions u...
CVE-2025-6537MEDIUM5.4The Namasha By Mdesign plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘playicon_title’ parame...
CVE-2025-5932MEDIUM4.3The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2025-5929MEDIUM5.4The The Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘clientId’ parameter in all ...
CVE-2025-5813MEDIUM5.3The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2025-5275MEDIUM4The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2025-6538MEDIUM5.4The Post Rating and Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter i...
CVE-2025-6383MEDIUM5.4The WP-PhotoNav plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's photonav shortcode in...
CVE-2025-6378MEDIUM6.4The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's di...
CVE-2025-6290MEDIUM5.4The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bra...
CVE-2025-6258MEDIUM6.4The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track short...
CVE-2025-5812MEDIUM4.3The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2025-5588MEDIUM6.4The Image Editor by Pixo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘download’ parameter ...
CVE-2025-5564MEDIUM6.4The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' s...
CVE-2025-5559MEDIUM5.4The TimeZoneCalculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'timezonecalcu...
CVE-2025-5540MEDIUM5.4The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-5535MEDIUM6.4The e.nigma buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcod...
CVE-2025-5488MEDIUM5.4The WP Masonry & Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wmi...
CVE-2025-3863MEDIUM4.3The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to improper authorization due to a missing cap...
CVE-2025-6664MEDIUM4.3A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now