2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2596 | MEDIUM | 5.3 | 0.2% | Mar 26, 2025 | Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL) |
| CVE-2025-27552 | MEDIUM | 4 | 0.1% | Mar 26, 2025 | DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This... |
| CVE-2025-27551 | MEDIUM | 4 | 0.1% | Mar 26, 2025 | DBIx::Class::EncodedColumn use the rand() function, which is not cryptographically secure to salt password hashes. This... |
| CVE-2025-1703 | MEDIUM | 6.4 | 0.3% | Mar 26, 2025 | The Ultimate Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all... |
| CVE-2025-1440 | MEDIUM | 5.3 | 0.3% | Mar 26, 2025 | The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_... |
| CVE-2025-1439 | MEDIUM | 5.4 | 0.2% | Mar 26, 2025 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'... |
| CVE-2025-1437 | MEDIUM | 5.4 | 0.2% | Mar 26, 2025 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'... |
| CVE-2025-1310 | MEDIUM | 6.5 | 0.7% | Mar 26, 2025 | The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2... |
| CVE-2025-2167 | MEDIUM | 5.4 | 0.2% | Mar 26, 2025 | The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events_list' shortcod... |
| CVE-2025-1784 | MEDIUM | 6.4 | 0.3% | Mar 26, 2025 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uagb ... |
| CVE-2025-30742 | MEDIUM | 5.3 | 0.4% | Mar 26, 2025 | httpd.c in atophttpd 2.8.0 has an off-by-one error and resultant out-of-bounds read because a certain 1024-character req... |
| CVE-2025-2576 | MEDIUM | 6.4 | 0.3% | Mar 26, 2025 | The Ayyash Studio — The kick-start kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up... |
| CVE-2025-2573 | MEDIUM | 6.4 | 0.3% | Mar 26, 2025 | The Amazing service box Addons For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable t... |
| CVE-2025-2165 | MEDIUM | 6.1 | 0.3% | Mar 26, 2025 | The SH Email Alert plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mid' parameter in all v... |
| CVE-2025-1490 | MEDIUM | 6.1 | 0.3% | Mar 26, 2025 | The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ para... |
| CVE-2025-2302 | MEDIUM | 6.4 | 0.3% | Mar 26, 2025 | The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aws_search_te... |
| CVE-2025-2276 | MEDIUM | 4.3 | 0.2% | Mar 26, 2025 | The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2025-30219 | MEDIUM | 6.1 | 0.2% | Mar 25, 2025 | RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that coul... |
| CVE-2025-30741 | MEDIUM | 4.3 | 0.3% | Mar 25, 2025 | Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This a... |
| CVE-2025-2312 | MEDIUM | 5.9 | 0.1% | Mar 25, 2025 | A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils ... |
| CVE-2025-26742 | MEDIUM | 6.5 | 0.2% | Mar 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery f... |
| CVE-2025-29932 | MEDIUM | 5.3 | 0.2% | Mar 25, 2025 | In JetBrains GoLand before 2025.1 an XXE during debugging was possible |
| CVE-2025-27633 | MEDIUM | 6.1 | 0.2% | Mar 25, 2025 | The TRMTracker web application is vulnerable to reflected Cross-site scripting attack. The application allows client-sid... |
| CVE-2025-27632 | MEDIUM | 6.1 | 0.2% | Mar 25, 2025 | A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value... |
| CVE-2025-27631 | MEDIUM | 6.5 | 0.3% | Mar 25, 2025 | The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now