2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2078 | MEDIUM | 4.8 | 0.2% | Mar 12, 2025 | The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers... |
| CVE-2025-2077 | MEDIUM | 6.1 | 0.3% | Mar 12, 2025 | The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter... |
| CVE-2025-2076 | MEDIUM | 4.8 | 0.2% | Mar 12, 2025 | The binlayerpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... |
| CVE-2025-1508 | MEDIUM | 5.3 | 0.4% | Mar 12, 2025 | The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ... |
| CVE-2025-2215 | MEDIUM | 5.1 | 0.5% | Mar 12, 2025 | A vulnerability classified as critical was found in Doufox up to 0.2.0. Affected by this vulnerability is an unknown fun... |
| CVE-2025-2214 | MEDIUM | 6.1 | 0.4% | Mar 12, 2025 | A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown proces... |
| CVE-2025-2213 | MEDIUM | 4.8 | 0.4% | Mar 11, 2025 | A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been declared as problematic. This vulnerability... |
| CVE-2025-2212 | MEDIUM | 6.1 | 0.4% | Mar 11, 2025 | A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an ... |
| CVE-2025-2211 | MEDIUM | 4.8 | 0.4% | Mar 11, 2025 | A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is s... |
| CVE-2025-2210 | MEDIUM | 4.8 | 0.4% | Mar 11, 2025 | A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulne... |
| CVE-2025-2209 | MEDIUM | 4.8 | 0.4% | Mar 11, 2025 | A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unkn... |
| CVE-2025-2208 | MEDIUM | 4.8 | 0.5% | Mar 11, 2025 | A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue aff... |
| CVE-2025-28943 | MEDIUM | 5.9 | 0.3% | Mar 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mylo2h2s DP ALTerm... |
| CVE-2025-28941 | MEDIUM | 4.3 | 0.2% | Mar 11, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ohtan Spam Byebye spam-byebye allows Cross Site Request Forgery.This ... |
| CVE-2025-28940 | MEDIUM | 4.3 | 0.2% | Mar 11, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in arkapravamajumder Back To Top backtotop allows Cross Site Request For... |
| CVE-2025-28938 | MEDIUM | 4.3 | 0.4% | Mar 11, 2025 | Missing Authorization vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Exploiting Incorrectly Conf... |
| CVE-2025-28937 | MEDIUM | 5.9 | 0.3% | Mar 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax... |
| CVE-2025-28936 | MEDIUM | 5.9 | 0.3% | Mar 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sakurapixel Lunar ... |
| CVE-2025-28930 | MEDIUM | 6.5 | 0.2% | Mar 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rodolphe MOULIN Li... |
| CVE-2025-28929 | MEDIUM | 6.5 | 0.2% | Mar 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tab... |
| CVE-2025-28927 | MEDIUM | 4.3 | 0.2% | Mar 11, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in A. Chappard Display Template Name display-template-name allows Cross ... |
| CVE-2025-28926 | MEDIUM | 5.9 | 0.3% | Mar 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in popeating Post Rea... |
| CVE-2025-28920 | MEDIUM | 5.3 | 0.3% | Mar 11, 2025 | Missing Authorization vulnerability in Jogesh Responsive Google Map responsive-google-map allows Exploiting Incorrectly ... |
| CVE-2025-28919 | MEDIUM | 6.5 | 0.2% | Mar 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shellbot Easy Imag... |
| CVE-2025-28918 | MEDIUM | 6.5 | 0.2% | Mar 11, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones Featured ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now