2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26939 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Counters ... |
| CVE-2025-26938 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Countdown... |
| CVE-2025-26937 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List... |
| CVE-2025-26928 | MEDIUM | 4.3 | 0.3% | Feb 25, 2025 | Missing Authorization vulnerability in Xfinitysoft Order Limit for WooCommerce wc-order-limit-lite allows Exploiting Inc... |
| CVE-2025-26926 | MEDIUM | 4.3 | 0.1% | Feb 25, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in fs-code Booknetic booknetic.This issue affects Booknetic: from n/a th... |
| CVE-2025-26913 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webandprint AR For... |
| CVE-2025-26912 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy El... |
| CVE-2025-26911 | MEDIUM | 4.3 | 0.3% | Feb 25, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard system... |
| CVE-2025-26904 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gal_op WP Responsi... |
| CVE-2025-26897 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Baden List Related... |
| CVE-2025-26896 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vpiwigo PiwigoPres... |
| CVE-2025-26893 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kiran Potphode Eas... |
| CVE-2025-26891 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana i... |
| CVE-2025-26887 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli EZ SQL Reports... |
| CVE-2025-26884 | MEDIUM | 5.4 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift ... |
| CVE-2025-26882 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Bui... |
| CVE-2025-26881 | MEDIUM | 6.5 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Sticky Co... |
| CVE-2025-26878 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in patternsinthecloud... |
| CVE-2025-26877 | MEDIUM | 5.4 | 0.2% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Front E... |
| CVE-2025-26876 | MEDIUM | 4.9 | 0.5% | Feb 25, 2025 | Path Traversal: '.../...//' vulnerability in CodeManas Search with Typesense search-with-typesense allows Path Traversal... |
| CVE-2025-1262 | MEDIUM | 5.3 | 0.3% | Feb 25, 2025 | The Advanced Google reCaptcha plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.2... |
| CVE-2025-1063 | MEDIUM | 5.3 | 0.3% | Feb 25, 2025 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Sensitive Info... |
| CVE-2025-27145 | MEDIUM | 6.1 | 0.4% | Feb 25, 2025 | copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The ... |
| CVE-2025-1645 | MEDIUM | 6.3 | 0.4% | Feb 25, 2025 | A vulnerability classified as critical was found in Benner Connecta 1.0.5330. Affected by this vulnerability is an unkno... |
| CVE-2025-1644 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | A vulnerability classified as problematic has been found in Benner ModernaNet up to 1.2.0. Affected is an unknown functi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now