2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4198 | MEDIUM | 6.1 | 0.1% | May 3, 2025 | The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3... |
| CVE-2025-4188 | MEDIUM | 6.1 | 0.1% | May 3, 2025 | The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ... |
| CVE-2025-4172 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The VerticalResponse Newsletter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2025-4170 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The Xavin's Review Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xrr'... |
| CVE-2025-4168 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode... |
| CVE-2025-47229 | MEDIUM | 5.5 | 0.2% | May 3, 2025 | libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion fa... |
| CVE-2025-3779 | MEDIUM | 6.4 | 0.2% | May 3, 2025 | The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in all ve... |
| CVE-2025-21572 | MEDIUM | 6.1 | 0.2% | May 2, 2025 | OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens thr... |
| CVE-2025-46332 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 ... |
| CVE-2025-4166 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in... |
| CVE-2025-2488 | MEDIUM | 6.1 | 0.2% | May 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis In... |
| CVE-2025-1301 | MEDIUM | 6.1 | 0.2% | May 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Info... |
| CVE-2025-47201 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaSc... |
| CVE-2025-3488 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher short... |
| CVE-2025-3858 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all version... |
| CVE-2025-3748 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Taxonomy Chain Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pn_chain_menu... |
| CVE-2025-3707 | MEDIUM | 6.5 | 0.4% | May 2, 2025 | The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject... |
| CVE-2025-3510 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all ver... |
| CVE-2025-1327 | MEDIUM | 4.3 | 0.2% | May 2, 2025 | The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.... |
| CVE-2025-1326 | MEDIUM | 4.3 | 0.2% | May 2, 2025 | The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th... |
| CVE-2025-4177 | MEDIUM | 5.3 | 0.3% | May 2, 2025 | The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on t... |
| CVE-2025-4131 | MEDIUM | 6.4 | 0.2% | May 2, 2025 | The GmapsMania plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gmap shortcode in all ... |
| CVE-2025-3670 | MEDIUM | 6.4 | 0.2% | May 2, 2025 | The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all... |
| CVE-2025-2880 | MEDIUM | 5.3 | 0.3% | May 2, 2025 | The Yame | Link In Bio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i... |
| CVE-2025-29825 | MEDIUM | 6.5 | 0.7% | May 2, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now