2025 CVE Vulnerabilities

45,185 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-49865MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Re...
CVE-2025-49864MEDIUM5.3Missing Authorization vulnerability in AFS Analytics AFS Analytics addfreestats allows Accessing Functionality Not Prope...
CVE-2025-49863MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP CodeUs Advanced...
CVE-2025-49862MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook St...
CVE-2025-49861MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timur Kamaev Kama ...
CVE-2025-49859MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in etruel WP Views Co...
CVE-2025-49858MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc...
CVE-2025-49857MEDIUM4.3Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-49856MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Cross Site Requ...
CVE-2025-49855MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meks Meks Flexible...
CVE-2025-49234MEDIUM6.5Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator allows Exploit...
CVE-2025-49178MEDIUM5.5A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the serv...
CVE-2025-49177MEDIUM6.1A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length...
CVE-2025-49175MEDIUM6.1A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the serve...
CVE-2025-48111MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Si...
CVE-2025-34508MEDIUM6.3A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could...
CVE-2025-6069MEDIUM4.3The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs po...
CVE-2025-5700MEDIUM6.4The Simple Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all...
CVE-2025-5291MEDIUM5.4The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2025-3880MEDIUM4.3The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2025-6050MEDIUM4.8Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin inter...
CVE-2025-40674MEDIUM5.1Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code ...
CVE-2025-6166MEDIUM5.1A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the func...
CVE-2025-5209MEDIUM4.8The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow hi...
CVE-2025-5673MEDIUM6.5The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the ‘prgSort...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now