2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2078MEDIUM4.8The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers...
CVE-2025-2077MEDIUM6.1The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter...
CVE-2025-2076MEDIUM4.8The binlayerpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u...
CVE-2025-1508MEDIUM5.3The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ...
CVE-2025-2215MEDIUM5.1A vulnerability classified as critical was found in Doufox up to 0.2.0. Affected by this vulnerability is an unknown fun...
CVE-2025-2214MEDIUM6.1A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown proces...
CVE-2025-2213MEDIUM4.8A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been declared as problematic. This vulnerability...
CVE-2025-2212MEDIUM6.1A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an ...
CVE-2025-2211MEDIUM4.8A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is s...
CVE-2025-2210MEDIUM4.8A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulne...
CVE-2025-2209MEDIUM4.8A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unkn...
CVE-2025-2208MEDIUM4.8A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue aff...
CVE-2025-28943MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mylo2h2s DP ALTerm...
CVE-2025-28941MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ohtan Spam Byebye spam-byebye allows Cross Site Request Forgery.This ...
CVE-2025-28940MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in arkapravamajumder Back To Top backtotop allows Cross Site Request For...
CVE-2025-28938MEDIUM4.3Missing Authorization vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Exploiting Incorrectly Conf...
CVE-2025-28937MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax...
CVE-2025-28936MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sakurapixel Lunar ...
CVE-2025-28930MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rodolphe MOULIN Li...
CVE-2025-28929MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tab...
CVE-2025-28927MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in A. Chappard Display Template Name display-template-name allows Cross ...
CVE-2025-28926MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in popeating Post Rea...
CVE-2025-28920MEDIUM5.3Missing Authorization vulnerability in Jogesh Responsive Google Map responsive-google-map allows Exploiting Incorrectly ...
CVE-2025-28919MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shellbot Easy Imag...
CVE-2025-28918MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones Featured ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now