2025 CVE Vulnerabilities
45,185 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49865 | MEDIUM | 4.3 | 0.1% | Jun 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Re... |
| CVE-2025-49864 | MEDIUM | 5.3 | 0.2% | Jun 17, 2025 | Missing Authorization vulnerability in AFS Analytics AFS Analytics addfreestats allows Accessing Functionality Not Prope... |
| CVE-2025-49863 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP CodeUs Advanced... |
| CVE-2025-49862 | MEDIUM | 5.9 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook St... |
| CVE-2025-49861 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timur Kamaev Kama ... |
| CVE-2025-49859 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in etruel WP Views Co... |
| CVE-2025-49858 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc... |
| CVE-2025-49857 | MEDIUM | 4.3 | 0.2% | Jun 17, 2025 | Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-49856 | MEDIUM | 4.3 | 0.1% | Jun 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Cross Site Requ... |
| CVE-2025-49855 | MEDIUM | 6.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meks Meks Flexible... |
| CVE-2025-49234 | MEDIUM | 6.5 | 0.3% | Jun 17, 2025 | Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator allows Exploit... |
| CVE-2025-49178 | MEDIUM | 5.5 | 0.2% | Jun 17, 2025 | A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the serv... |
| CVE-2025-49177 | MEDIUM | 6.1 | 0.4% | Jun 17, 2025 | A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length... |
| CVE-2025-49175 | MEDIUM | 6.1 | 0.3% | Jun 17, 2025 | A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the serve... |
| CVE-2025-48111 | MEDIUM | 4.3 | 0.1% | Jun 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Si... |
| CVE-2025-34508 | MEDIUM | 6.3 | 62.1% | Jun 17, 2025 | A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could... |
| CVE-2025-6069 | MEDIUM | 4.3 | 0.5% | Jun 17, 2025 | The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs po... |
| CVE-2025-5700 | MEDIUM | 6.4 | 0.2% | Jun 17, 2025 | The Simple Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all... |
| CVE-2025-5291 | MEDIUM | 5.4 | 0.2% | Jun 17, 2025 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2025-3880 | MEDIUM | 4.3 | 0.2% | Jun 17, 2025 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2025-6050 | MEDIUM | 4.8 | 0.3% | Jun 17, 2025 | Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin inter... |
| CVE-2025-40674 | MEDIUM | 5.1 | 0.4% | Jun 17, 2025 | Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code ... |
| CVE-2025-6166 | MEDIUM | 5.1 | 0.5% | Jun 17, 2025 | A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the func... |
| CVE-2025-5209 | MEDIUM | 4.8 | 0.2% | Jun 17, 2025 | The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2025-5673 | MEDIUM | 6.5 | 0.3% | Jun 17, 2025 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the ‘prgSort... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now