2025 CVE Vulnerabilities

45,199 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-5928MEDIUM4.3The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up...
CVE-2025-5926MEDIUM6.1The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0...
CVE-2025-5841MEDIUM6.4The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all ver...
CVE-2025-5233MEDIUM6.4The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versi...
CVE-2025-5123MEDIUM5.4The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ p...
CVE-2025-4586MEDIUM5.4The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' sh...
CVE-2025-4585MEDIUM5.4The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode ...
CVE-2025-4584MEDIUM5.4The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' short...
CVE-2025-4228MEDIUM4.6An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated admi...
CVE-2025-4233MEDIUM5.1An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypa...
CVE-2025-41234MEDIUM6.5Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to ...
CVE-2025-41233MEDIUM6.8Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated...
CVE-2025-49589MEDIUM6.1PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE fu...
CVE-2025-44091MEDIUM5.4yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function.
CVE-2025-4418MEDIUM6.7An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 ...
CVE-2025-4417MEDIUM6.9A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploi...
CVE-2025-2745MEDIUM6.5A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could al...
CVE-2025-49579MEDIUM4.8Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings ...
CVE-2025-49578MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `La...
CVE-2025-49577MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inse...
CVE-2025-49576MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title an...
CVE-2025-49575MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted...
CVE-2025-49081MEDIUM4.9There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to se...
CVE-2025-36573MEDIUM5.5Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vul...
CVE-2025-29744MEDIUM5.4pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now