2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13725MEDIUM6.5The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to ar...
CVE-2025-14632MEDIUM4.4The Filr – Secure document library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unrestricted fi...
CVE-2025-14450MEDIUM6.5The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2025-14075MEDIUM5.3The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2025-12718MEDIUM5.8The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6...
CVE-2025-12002MEDIUM5.9The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including...
CVE-2025-56451MEDIUM6.1Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue paramete...
CVE-2025-69581MEDIUM5.5An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user i...
CVE-2025-51602MEDIUM4.8mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01...
CVE-2025-43904MEDIUM4.2In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user ...
CVE-2025-43508MEDIUM5.5A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able ...
CVE-2025-24531MEDIUM6.7In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a...
CVE-2025-24089MEDIUM5.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ...
CVE-2025-29943MEDIUM4.6Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU ...
CVE-2025-15104MEDIUM5.3Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arb...
CVE-2025-14435MEDIUM6.5Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API er...
CVE-2025-14822MEDIUM6.5Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authentica...
CVE-2025-14757MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions ...
CVE-2025-14375MEDIUM6.1The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflec...
CVE-2025-14853MEDIUM4.3The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1....
CVE-2025-14793MEDIUM5The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u...
CVE-2025-15527MEDIUM4.3The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 ...
CVE-2025-15526MEDIUM5.3The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includi...
CVE-2025-15370MEDIUM4.3The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D...
CVE-2025-14982MEDIUM4.3The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now