2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1620MEDIUM4.8The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which coul...
CVE-2025-1619MEDIUM4.8The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which coul...
CVE-2025-24856MEDIUM4.2An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account li...
CVE-2025-30077MEDIUM6.2Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString ...
CVE-2025-2335MEDIUM5.1A vulnerability classified as problematic was found in Drivin Soluções up to 20250226. This vulnerability affects unknow...
CVE-2025-26940MEDIUM6.3Path Traversal vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through...
CVE-2025-26924MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code In...
CVE-2025-26899MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce...
CVE-2025-26895MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maennchen1.de m1.D...
CVE-2025-25225MEDIUM6.5A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated atta...
CVE-2025-2323MEDIUM5.3A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vuln...
CVE-2025-2321MEDIUM6.5A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this is...
CVE-2025-1530MEDIUM4.3The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0....
CVE-2025-1057MEDIUM4.3A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prev...
CVE-2025-2325MEDIUM6.1The WP Test Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to...
CVE-2025-1773MEDIUM6.1The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions...
CVE-2025-2267MEDIUM6.5The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due t...
CVE-2025-2164MEDIUM6.1The pixelstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' and 'sortby' param...
CVE-2025-2163MEDIUM5.4The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-1670MEDIUM6.5The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter...
CVE-2025-1669MEDIUM6.5The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' act...
CVE-2025-1668MEDIUM5.4The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a miss...
CVE-2025-1667MEDIUM4.3The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing...
CVE-2025-29782MEDIUM5.4WeGIA is Web manager for charitable institutions A Stored Cross-Site Scripting (XSS) vulnerability was identified in the...
CVE-2025-29771MEDIUM5.3HtmlSanitizer is a client-side HTML Sanitizer. Versions prior to 2.0.3 have a cross-site scripting vulnerability when th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now