2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26582HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems tinymce-adva...
CVE-2025-26580HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Complete SEO Page/Post Specific Social Share Buttons pagepost-specifi...
CVE-2025-26578HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in mathieuhays Simple Documentation client-documentation allows Stored X...
CVE-2025-26577HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in daxiawp DX-auto-publish dx-auto-publish allows Stored XSS.This issue ...
CVE-2025-26572HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in jesseheap WP PHPList phplist-form-integration allows Cross Site Reque...
CVE-2025-26571HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in wibiya Wibiya Toolbar wibiya allows Cross Site Request Forgery.This i...
CVE-2025-26570HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in uamv Glance That allows Cross Site Request Forgery. This issue affec...
CVE-2025-26569HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Callmeforsox Post Thumbs allows Stored XSS. This issue affects Post ...
CVE-2025-26568HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in jensmueller Easy Amazon Product Information easy-amazon-product-infor...
CVE-2025-26562HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Shambhu Patnaik RSS Filter rss-filter allows Stored XSS.This issue af...
CVE-2025-26552HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in badrHan Naver Synd...
CVE-2025-26551HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sureshdsk Bootstra...
CVE-2025-26550HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Kunal Shivale Global Meta Keyword & Description global-meta-keyword-a...
CVE-2025-26549HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in pa1 WP Html Page Sitemap wp-html-page-sitemap allows Stored XSS.This ...
CVE-2025-26547HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin my-loginlogout allows Stored XSS...
CVE-2025-26545HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in shisuh Related Posts Line-up-Exactly by Milliard related-posts-line-u...
CVE-2025-26543HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Pukhraj Suthar Simple Responsive Menu simple-responsive-menu allows S...
CVE-2025-1247HIGH8.3A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use fie...
CVE-2025-1270HIGH7.1Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access...
CVE-2025-1094HIGH8.1Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescap...
CVE-2025-21700HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: sched: Disallow replacing of child qdisc from ...
CVE-2025-0816HIGH7.1CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ...
CVE-2025-0815HIGH7.1CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ...
CVE-2025-0327HIGH8.5CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and...
CVE-2025-1070HIGH8.1CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable wh...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now