2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4198MEDIUM6.1The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3...
CVE-2025-4188MEDIUM6.1The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ...
CVE-2025-4172MEDIUM6.4The VerticalResponse Newsletter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2025-4170MEDIUM6.4The Xavin's Review Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xrr'...
CVE-2025-4168MEDIUM6.4The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode...
CVE-2025-47229MEDIUM5.5libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion fa...
CVE-2025-3779MEDIUM6.4The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in all ve...
CVE-2025-21572MEDIUM6.1OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens thr...
CVE-2025-46332MEDIUM6.5Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 ...
CVE-2025-4166MEDIUM6.5Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in...
CVE-2025-2488MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis In...
CVE-2025-1301MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Info...
CVE-2025-47201MEDIUM5.4In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaSc...
CVE-2025-3488MEDIUM5.4The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher short...
CVE-2025-3858MEDIUM5.4The Formality plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all version...
CVE-2025-3748MEDIUM5.4The Taxonomy Chain Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pn_chain_menu...
CVE-2025-3707MEDIUM6.5The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject...
CVE-2025-3510MEDIUM5.4The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in all ver...
CVE-2025-1327MEDIUM4.3The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2....
CVE-2025-1326MEDIUM4.3The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th...
CVE-2025-4177MEDIUM5.3The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on t...
CVE-2025-4131MEDIUM6.4The GmapsMania plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gmap shortcode in all ...
CVE-2025-3670MEDIUM6.4The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all...
CVE-2025-2880MEDIUM5.3The Yame | Link In Bio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i...
CVE-2025-29825MEDIUM6.5User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now