2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1627MEDIUM5.4The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them ...
CVE-2025-1626MEDIUM5.4The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before output...
CVE-2025-1625MEDIUM5.4The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputti...
CVE-2025-2892MEDIUM5.4The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ...
CVE-2025-23167MEDIUM6.5A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required...
CVE-2025-23164MEDIUM4.4A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the re...
CVE-2025-4904MEDIUM5.3A vulnerability has been found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. This vulnerabilit...
CVE-2025-4901MEDIUM6.5A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerabi...
CVE-2025-4898MEDIUM5.4A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This...
CVE-2025-4894MEDIUM5.9A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391...
CVE-2025-4893MEDIUM6.3A vulnerability classified as critical has been found in jammy928 CoinExchange_CryptoExchange_Java up to 8adf508b996020d...
CVE-2025-4868MEDIUM6.3A vulnerability was found in merikbest ecommerce-spring-reactjs up to 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd. It has b...
CVE-2025-4862MEDIUM6.1A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affe...
CVE-2025-3715MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text parameter in a...
CVE-2025-4860MEDIUM4.8A vulnerability classified as problematic has been found in D-Link DAP-2695 120b36r137_ALL_en_20210528. Affected is an u...
CVE-2025-4859MEDIUM4.8A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been rated as problematic. This issue af...
CVE-2025-4858MEDIUM4.8A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been declared as problematic. This vulne...
CVE-2025-4850MEDIUM6.3A vulnerability classified as critical has been found in TOTOLINK N300RH 6.1c.1390_B20191101. This affects the function ...
CVE-2025-4838MEDIUM5.3A vulnerability, which was classified as problematic, was found in kanwangzjm Funiture up to 71ca0fb0658b3d839d9e049ac36...
CVE-2025-47931MEDIUM6.1LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Sit...
CVE-2025-4101MEDIUM4.3The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is vulnerable to unauthorized loss...
CVE-2025-4669MEDIUM5.4The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpbc shortcod...
CVE-2025-3888MEDIUM5.4The Jupiter X Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File inclusion in all versi...
CVE-2025-3527MEDIUM5.4The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2025-4610MEDIUM6.4The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now