2025 CVE Vulnerabilities

45,191 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6109MEDIUM4.3A vulnerability was found in javahongxi whatsmars 2021.4.0. It has been rated as problematic. Affected by this issue is ...
CVE-2025-6108MEDIUM6.3A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa. It has b...
CVE-2025-6106MEDIUM4.3A vulnerability was found in WuKongOpenSource WukongCRM 9.0 and classified as problematic. This issue affects some unkno...
CVE-2025-6101MEDIUM5.5A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_m...
CVE-2025-6100MEDIUM6.3A vulnerability was found in realguoshuai open-video-cms 1.0. It has been rated as critical. This issue affects some unk...
CVE-2025-6099MEDIUM5.5A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared ...
CVE-2025-6093MEDIUM5.5A vulnerability classified as critical was found in uYanki board-stm32f103rc-berial up to 84daed541609cb7b46854cc6672a27...
CVE-2025-5964MEDIUM6.5A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to...
CVE-2025-6092MEDIUM4.3A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this ...
CVE-2025-5990MEDIUM5.4An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a ...
CVE-2025-22854MEDIUM6.9Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal u...
CVE-2025-6089MEDIUM6.1A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability a...
CVE-2025-5337MEDIUM5.4The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-5238MEDIUM6.4The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter i...
CVE-2025-4667MEDIUM6.4The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sto...
CVE-2025-6070MEDIUM6.5The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,...
CVE-2025-6064MEDIUM6.1The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-6063MEDIUM6.1The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-6062MEDIUM4.3The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-6061MEDIUM6.4The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcod...
CVE-2025-6055MEDIUM6.1The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2025-6040MEDIUM6.1The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-5589MEDIUM6.4The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-cla...
CVE-2025-5336MEDIUM6.4The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter i...
CVE-2025-4592MEDIUM4.3The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now