2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-49975MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This iss...
CVE-2025-49974MEDIUM4.3Missing Authorization vulnerability in upstreamplugin UpStream: a Project Management Plugin for WordPress upstream allow...
CVE-2025-49973MEDIUM4.3Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Siz...
CVE-2025-49972MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy tm-replace-howdy allows Cross Site Reques...
CVE-2025-49971MEDIUM4.3Missing Authorization vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Exploiting ...
CVE-2025-49970MEDIUM4.3Missing Authorization vulnerability in sparklewpthemes Hello FSE Blog hello-fse-blog allows Exploiting Incorrectly Confi...
CVE-2025-49969MEDIUM4.3Missing Authorization vulnerability in Zara 4 Zara 4 Image Compression zara-4 allows Exploiting Incorrectly Configured A...
CVE-2025-49968MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Oganro XML Travel Portal Widget oganro-reservation-widget allows Cros...
CVE-2025-49967MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in marcusjansen Live Sports Streamthunder live-sports-streamthunder allo...
CVE-2025-49966MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Oganro Oganro Travel Portal Search Widget for HotelBeds APITUDE API o...
CVE-2025-49965MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Oganro PixelBeds Channel Manager and Hotel Booking Engine pixelbeds-c...
CVE-2025-49964MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in indgeek ClipLink cliplink allows Cross Site Request Forgery.This issu...
CVE-2025-3228MEDIUM4.3Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr...
CVE-2025-3227MEDIUM4.3Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr...
CVE-2025-32876MEDIUM6.8An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does no...
CVE-2025-32875MEDIUM5.7An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither in...
CVE-2025-6341MEDIUM4.3A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. This vulnerability ...
CVE-2025-6340MEDIUM5.4A vulnerability classified as problematic has been found in code-projects School Fees Payment System 1.0. This affects a...
CVE-2025-6336MEDIUM6.5A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an...
CVE-2025-38083MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: net_sched: prio: fix a race in prio_tune() Gerrard...
CVE-2025-5963MEDIUM4.8The Postbox's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-envir...
CVE-2025-5255MEDIUM4.8The Phoenix Code's configuration on macOS, specifically the presence of entitlements: "com.apple.security.cs.allow-dyld-...
CVE-2025-6257MEDIUM6.4The Euro FxRef Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cur...
CVE-2025-50054MEDIUM5.5Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user proc...
CVE-2025-5125MEDIUM4.8The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the dat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now