2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2596MEDIUM5.3Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)
CVE-2025-27552MEDIUM4DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This...
CVE-2025-27551MEDIUM4DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This...
CVE-2025-1703MEDIUM6.4The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all...
CVE-2025-1440MEDIUM5.3The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_...
CVE-2025-1439MEDIUM5.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'...
CVE-2025-1437MEDIUM5.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'...
CVE-2025-1310MEDIUM6.5The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2...
CVE-2025-2167MEDIUM5.4The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcod...
CVE-2025-1784MEDIUM6.4The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb ...
CVE-2025-30742MEDIUM5.3httpd.c in atophttpd 2.8.0 has an off-by-one error and resultant out-of-bounds read because a certain 1024-character req...
CVE-2025-2576MEDIUM6.4The Ayyash Studio — The kick-start kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up...
CVE-2025-2573MEDIUM6.4The Amazing service box Addons For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable t...
CVE-2025-2165MEDIUM6.1The SH Email Alert plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mid' parameter in all v...
CVE-2025-1490MEDIUM6.1The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ para...
CVE-2025-2302MEDIUM6.4The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aws_search_te...
CVE-2025-2276MEDIUM4.3The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2025-30219MEDIUM6.1RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that coul...
CVE-2025-30741MEDIUM4.3Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This a...
CVE-2025-2312MEDIUM5.9A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils ...
CVE-2025-26742MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery f...
CVE-2025-29932MEDIUM5.3In JetBrains GoLand before 2025.1 an XXE during debugging was possible
CVE-2025-27633MEDIUM6.1The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-sid...
CVE-2025-27632MEDIUM6.1A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value...
CVE-2025-27631MEDIUM6.5The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now