2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1362MEDIUM4.3The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF c...
CVE-2025-2114MEDIUM6.3A vulnerability, which was classified as problematic, has been found in Shenzhen Sixun Software Sixun Shanghui Group Bus...
CVE-2025-27840MEDIUM6.8Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
CVE-2025-1664MEDIUM5.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2025-1783MEDIUM5.4The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versio...
CVE-2025-1325MEDIUM6.3The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode executi...
CVE-2025-1324MEDIUM5.4The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2025-1322MEDIUM4.3The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all...
CVE-2025-1287MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2025-1504MEDIUM6.5The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2...
CVE-2025-1481MEDIUM4.3The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2025-1261MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting ...
CVE-2025-27826MEDIUM6.4An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanit...
CVE-2025-27825MEDIUM6.4An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently san...
CVE-2025-27824MEDIUM6.4An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1 for Backdrop CMS. It doesn't sufficient...
CVE-2025-27823MEDIUM6.4An issue was discovered in the Mail Disguise module before 1.x-1.0.5 for Backdrop CMS. It enables a website to obfuscate...
CVE-2025-26643MEDIUM5.4The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ...
CVE-2025-27518MEDIUM6.9Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for productio...
CVE-2025-27152MEDIUM5.3axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather tha...
CVE-2025-25617MEDIUM4.3Incorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.
CVE-2025-2090MEDIUM5.1A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this is...
CVE-2025-2089MEDIUM5.4A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerabil...
CVE-2025-2087MEDIUM6.1A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects s...
CVE-2025-2086MEDIUM6.1A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown co...
CVE-2025-2085MEDIUM6.1A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now