2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2109MEDIUM5.8The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Server-Side Request For...
CVE-2025-2635MEDIUM6.1The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remov...
CVE-2025-2542MEDIUM6.4The Your Simple SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in al...
CVE-2025-2559MEDIUM4.9A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until exp...
CVE-2025-2510MEDIUM5.5The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter ...
CVE-2025-2744MEDIUM5.4A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknow...
CVE-2025-2252MEDIUM5.3The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Sensit...
CVE-2025-1320MEDIUM4.3The teachPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9....
CVE-2025-2224MEDIUM5.3The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to...
CVE-2025-27810MEDIUM4.8Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uniniti...
CVE-2025-27809MEDIUM5.4Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arb...
CVE-2025-1798MEDIUM6.1The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users th...
CVE-2025-0845MEDIUM6.4The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versi...
CVE-2025-2733MEDIUM6.3A vulnerability classified as critical has been found in mannaandpoem OpenManus up to 2025.3.13. This affects an unknown...
CVE-2025-24513MEDIUM4.8A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided d...
CVE-2025-2716MEDIUM5.1A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unk...
CVE-2025-2715MEDIUM5.1A vulnerability classified as problematic has been found in timschofield webERP up to 5.0.0.rc+13. This affects an unkno...
CVE-2025-2714MEDIUM5.3A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is...
CVE-2025-2712MEDIUM6.1A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerabilit...
CVE-2025-2711MEDIUM6.1A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown func...
CVE-2025-2710MEDIUM6.1A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown proc...
CVE-2025-2709MEDIUM6.1A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unkn...
CVE-2025-30163MEDIUM4.7Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Node based network policies (...
CVE-2025-30162MEDIUM4.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who use Gate...
CVE-2025-2748MEDIUM6.1The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload function...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now