2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-41363MEDIUM5.3In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing...
CVE-2025-41362MEDIUM5.3Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to st...
CVE-2025-5757MEDIUM5.4A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affec...
CVE-2025-5727MEDIUM5.4A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This af...
CVE-2025-5703MEDIUM5.4The StageShow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘anchor’ parameter in all versio...
CVE-2025-5699MEDIUM5.5The Developer Formatter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom CSS in all vers...
CVE-2025-5686MEDIUM6.4The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode...
CVE-2025-5586MEDIUM6.4The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-5565MEDIUM6.4The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all...
CVE-2025-5563MEDIUM6.5The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, a...
CVE-2025-5541MEDIUM6.4The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcod...
CVE-2025-5538MEDIUM6.4The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' sho...
CVE-2025-5536MEDIUM6.4The Freemind Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'freemind' shortc...
CVE-2025-5534MEDIUM6.4The ESV Bible Shortcode for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2025-5533MEDIUM6.4The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kbalert' shortcod...
CVE-2025-5019MEDIUM5.4The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable...
CVE-2025-4966MEDIUM6.1The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-4964MEDIUM4.9The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter ...
CVE-2025-48910MEDIUM5.5Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect avail...
CVE-2025-48908MEDIUM6.7Ability Auto Startup service vulnerability in the foundation process Impact: Successful exploitation of this vulnerabili...
CVE-2025-48907MEDIUM6.2Deserialization vulnerability in the IPC module Impact: Successful exploitation of this vulnerability may affect availab...
CVE-2025-48904MEDIUM6.2Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerabi...
CVE-2025-48902MEDIUM6.6Vulnerability of uncontrolled system resource applications in the setting module Impact: Successful exploitation of this...
CVE-2025-2935MEDIUM5.4The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Requ...
CVE-2025-5726MEDIUM5.4A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now