2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2109 | MEDIUM | 5.8 | 0.4% | Mar 25, 2025 | The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request For... |
| CVE-2025-2635 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remov... |
| CVE-2025-2542 | MEDIUM | 6.4 | 0.3% | Mar 25, 2025 | The Your Simple SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in al... |
| CVE-2025-2559 | MEDIUM | 4.9 | 0.6% | Mar 25, 2025 | A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until exp... |
| CVE-2025-2510 | MEDIUM | 5.5 | 0.2% | Mar 25, 2025 | The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter ... |
| CVE-2025-2744 | MEDIUM | 5.4 | 0.7% | Mar 25, 2025 | A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknow... |
| CVE-2025-2252 | MEDIUM | 5.3 | 0.4% | Mar 25, 2025 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensit... |
| CVE-2025-1320 | MEDIUM | 4.3 | 0.2% | Mar 25, 2025 | The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.... |
| CVE-2025-2224 | MEDIUM | 5.3 | 0.4% | Mar 25, 2025 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to... |
| CVE-2025-27810 | MEDIUM | 4.8 | 0.3% | Mar 25, 2025 | Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uniniti... |
| CVE-2025-27809 | MEDIUM | 5.4 | 0.2% | Mar 25, 2025 | Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arb... |
| CVE-2025-1798 | MEDIUM | 6.1 | 0.2% | Mar 25, 2025 | The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users th... |
| CVE-2025-0845 | MEDIUM | 6.4 | 0.2% | Mar 25, 2025 | The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versi... |
| CVE-2025-2733 | MEDIUM | 6.3 | 1.4% | Mar 25, 2025 | A vulnerability classified as critical has been found in mannaandpoem OpenManus up to 2025.3.13. This affects an unknown... |
| CVE-2025-24513 | MEDIUM | 4.8 | 3.5% | Mar 25, 2025 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided d... |
| CVE-2025-2716 | MEDIUM | 5.1 | 0.5% | Mar 24, 2025 | A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unk... |
| CVE-2025-2715 | MEDIUM | 5.1 | 0.3% | Mar 24, 2025 | A vulnerability classified as problematic has been found in timschofield webERP up to 5.0.0.rc+13. This affects an unkno... |
| CVE-2025-2714 | MEDIUM | 5.3 | 0.4% | Mar 24, 2025 | A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is... |
| CVE-2025-2712 | MEDIUM | 6.1 | 0.8% | Mar 24, 2025 | A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerabilit... |
| CVE-2025-2711 | MEDIUM | 6.1 | 0.9% | Mar 24, 2025 | A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown func... |
| CVE-2025-2710 | MEDIUM | 6.1 | 0.9% | Mar 24, 2025 | A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown proc... |
| CVE-2025-2709 | MEDIUM | 6.1 | 0.9% | Mar 24, 2025 | A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unkn... |
| CVE-2025-30163 | MEDIUM | 4.7 | 0.2% | Mar 24, 2025 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (... |
| CVE-2025-30162 | MEDIUM | 4.3 | 0.2% | Mar 24, 2025 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gate... |
| CVE-2025-2748 | MEDIUM | 6.1 | 59.1% | Mar 24, 2025 | The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload function... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now