2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48497 | MEDIUM | 5.1 | 0.1% | Jun 26, 2025 | Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a speci... |
| CVE-2025-41404 | MEDIUM | 5.3 | 0.2% | Jun 26, 2025 | Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is e... |
| CVE-2025-3279 | MEDIUM | 6.5 | 0.3% | Jun 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18... |
| CVE-2025-1754 | MEDIUM | 5.3 | 0.2% | Jun 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18... |
| CVE-2025-6546 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The Drive Folder Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tablecssclass’ para... |
| CVE-2025-6540 | MEDIUM | 6.4 | 0.2% | Jun 26, 2025 | The web-cam plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter in all versions u... |
| CVE-2025-6537 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The Namasha By Mdesign plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘playicon_title’ parame... |
| CVE-2025-5932 | MEDIUM | 4.3 | 0.2% | Jun 26, 2025 | The Homerunner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2025-5929 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The The Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘clientId’ parameter in all ... |
| CVE-2025-5813 | MEDIUM | 5.3 | 0.2% | Jun 26, 2025 | The Amazon Products to WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2025-5275 | MEDIUM | 4 | 0.2% | Jun 26, 2025 | The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul... |
| CVE-2025-6538 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The Post Rating and Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter i... |
| CVE-2025-6383 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The WP-PhotoNav plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's photonav shortcode in... |
| CVE-2025-6378 | MEDIUM | 6.4 | 0.2% | Jun 26, 2025 | The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's di... |
| CVE-2025-6290 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bra... |
| CVE-2025-6258 | MEDIUM | 6.4 | 0.2% | Jun 26, 2025 | The WP SoundSystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsstm-track short... |
| CVE-2025-5812 | MEDIUM | 4.3 | 0.2% | Jun 26, 2025 | The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2025-5588 | MEDIUM | 6.4 | 0.2% | Jun 26, 2025 | The Image Editor by Pixo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘download’ parameter ... |
| CVE-2025-5564 | MEDIUM | 6.4 | 0.2% | Jun 26, 2025 | The GC Social Wall plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gc_social_wall' s... |
| CVE-2025-5559 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The TimeZoneCalculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'timezonecalcu... |
| CVE-2025-5540 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-5535 | MEDIUM | 6.4 | 0.2% | Jun 26, 2025 | The e.nigma buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcod... |
| CVE-2025-5488 | MEDIUM | 5.4 | 0.2% | Jun 26, 2025 | The WP Masonry & Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wmi... |
| CVE-2025-3863 | MEDIUM | 4.3 | 0.2% | Jun 26, 2025 | The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to improper authorization due to a missing cap... |
| CVE-2025-6664 | MEDIUM | 4.3 | 0.2% | Jun 25, 2025 | A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now