2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-3743MEDIUM5.3The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to...
CVE-2025-3923MEDIUM5.3The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure...
CVE-2025-3861MEDIUM5.4The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modifi...
CVE-2025-2580MEDIUM4.9The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a...
CVE-2025-0671MEDIUM6.1The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which co...
CVE-2025-46599MEDIUM6.8CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that,...
CVE-2025-3775MEDIUM6.5The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2025-3752MEDIUM6.4The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-46595MEDIUM6.4An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to ...
CVE-2025-46547MEDIUM6.1In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an a...
CVE-2025-46545MEDIUM4.8In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an adm...
CVE-2025-46544MEDIUM6.5In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.
CVE-2025-3749MEDIUM6.4The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cal_size’ parameter in all...
CVE-2025-43861MEDIUM5.4ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to...
CVE-2025-29529MEDIUM6.5ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via th...
CVE-2025-46542MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeXpert Xpert T...
CVE-2025-46541MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elrata_ WP-reCAPTC...
CVE-2025-46540MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Mok GNA Sear...
CVE-2025-46538MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webplanetsoft Inli...
CVE-2025-46536MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RichardHarrison Ca...
CVE-2025-46534MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DanielRiera Image ...
CVE-2025-46533MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdrift.no Landing...
CVE-2025-46532MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Haris Zulfiqar Too...
CVE-2025-46531MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) wo...
CVE-2025-46529MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StressFree Sites B...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now