2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1748MEDIUM4.7HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to mod...
CVE-2025-1747MEDIUM4.7HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to mod...
CVE-2025-1746MEDIUM6.1Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute...
CVE-2025-22271MEDIUM6.9The application or its infrastructure allows for IP address spoofing by providing its own value in the "X-Forwarded-For"...
CVE-2025-1300MEDIUM6.1CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ...
CVE-2025-22492MEDIUM6.3The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this str...
CVE-2025-22491MEDIUM6.7The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application...
CVE-2025-1662MEDIUM6.4The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl...
CVE-2025-1560MEDIUM5.4The WOW Entrance Effects (WEE!) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wee'...
CVE-2025-1571MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's An...
CVE-2025-1405MEDIUM5.4The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_produ...
CVE-2025-0764MEDIUM6.5The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the '...
CVE-2025-1513MEDIUM6.1The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Str...
CVE-2025-1511MEDIUM6.1The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln...
CVE-2025-1506MEDIUM4.3The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ...
CVE-2025-1757MEDIUM5.4The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2025-1505MEDIUM6.1The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' p...
CVE-2025-0801MEDIUM4.3The RateMyAgent Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-23225MEDIUM6.5IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the im...
CVE-2025-0823MEDIUM6.5IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse direc...
CVE-2025-25728MEDIUM6.5Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send commu...
CVE-2025-25727MEDIUM6.2Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store pass...
CVE-2025-1681MEDIUM5.4The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing c...
CVE-2025-24832MEDIUM5.5Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products a...
CVE-2025-25730MEDIUM4.6An issue in Motorola Mobility Droid Razr HD (Model XT926) System Version: 9.18.94.XT926.Verizon.en.US allows physically ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now