2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1620 | MEDIUM | 4.8 | 0.2% | Mar 16, 2025 | The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which coul... |
| CVE-2025-1619 | MEDIUM | 4.8 | 0.2% | Mar 16, 2025 | The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which coul... |
| CVE-2025-24856 | MEDIUM | 4.2 | 0.2% | Mar 16, 2025 | An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account li... |
| CVE-2025-30077 | MEDIUM | 6.2 | 0.1% | Mar 16, 2025 | Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString ... |
| CVE-2025-2335 | MEDIUM | 5.1 | 0.3% | Mar 16, 2025 | A vulnerability classified as problematic was found in Drivin Soluções up to 20250226. This vulnerability affects unknow... |
| CVE-2025-26940 | MEDIUM | 6.3 | 0.4% | Mar 15, 2025 | Path Traversal vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a through... |
| CVE-2025-26924 | MEDIUM | 6.5 | 0.2% | Mar 15, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code In... |
| CVE-2025-26899 | MEDIUM | 6.5 | 0.2% | Mar 15, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce... |
| CVE-2025-26895 | MEDIUM | 6.5 | 0.2% | Mar 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maennchen1.de m1.D... |
| CVE-2025-25225 | MEDIUM | 6.5 | 0.1% | Mar 15, 2025 | A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated atta... |
| CVE-2025-2323 | MEDIUM | 5.3 | 0.4% | Mar 15, 2025 | A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vuln... |
| CVE-2025-2321 | MEDIUM | 6.5 | 0.4% | Mar 15, 2025 | A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this is... |
| CVE-2025-1530 | MEDIUM | 4.3 | 0.2% | Mar 15, 2025 | The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.... |
| CVE-2025-1057 | MEDIUM | 4.3 | 0.4% | Mar 15, 2025 | A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prev... |
| CVE-2025-2325 | MEDIUM | 6.1 | 0.3% | Mar 15, 2025 | The WP Test Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to... |
| CVE-2025-1773 | MEDIUM | 6.1 | 0.2% | Mar 15, 2025 | The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions... |
| CVE-2025-2267 | MEDIUM | 6.5 | 0.3% | Mar 15, 2025 | The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due t... |
| CVE-2025-2164 | MEDIUM | 6.1 | 0.3% | Mar 15, 2025 | The pixelstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' and 'sortby' param... |
| CVE-2025-2163 | MEDIUM | 5.4 | 0.2% | Mar 15, 2025 | The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-1670 | MEDIUM | 6.5 | 0.3% | Mar 15, 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter... |
| CVE-2025-1669 | MEDIUM | 6.5 | 0.3% | Mar 15, 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'addNotify' act... |
| CVE-2025-1668 | MEDIUM | 5.4 | 0.3% | Mar 15, 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to arbitrary user deletion due to a miss... |
| CVE-2025-1667 | MEDIUM | 4.3 | 0.3% | Mar 15, 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing... |
| CVE-2025-29782 | MEDIUM | 5.4 | 0.3% | Mar 14, 2025 | WeGIA is Web manager for charitable institutions A Stored Cross-Site Scripting (XSS) vulnerability was identified in the... |
| CVE-2025-29771 | MEDIUM | 5.3 | 0.4% | Mar 14, 2025 | HtmlSanitizer is a client-side HTML Sanitizer. Versions prior to 2.0.3 have a cross-site scripting vulnerability when th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now