2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1106MEDIUM6.5A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/res...
CVE-2025-1105MEDIUM6.1A vulnerability was found in SiberianCMS 4.20.6. It has been rated as problematic. Affected by this issue is some unknow...
CVE-2025-1103MEDIUM6.5A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the funct...
CVE-2025-25069MEDIUM6.5A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" a...
CVE-2025-25168MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Black and White BookPress – For Book Authors book-press allows Cross-...
CVE-2025-25166MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in gabrieldarezzo InLocation inlocation allows Stored XSS.This issue aff...
CVE-2025-25160MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker style-tweaker allows Stored XSS.This issue ...
CVE-2025-25146MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in saleandro Songkick Concerts and Festivals songkick-concerts-and-festi...
CVE-2025-25145MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in jordan.hatch Infusionsoft Analytics infusionsoft-web-tracker allows C...
CVE-2025-25143MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ibasit GlobalQuran globalquran allows Cross Site Request Forgery.This...
CVE-2025-25136MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shujahat21 Optimat...
CVE-2025-25120MEDIUM4.3Missing Authorization vulnerability in Melodic Media Slide Banners slide-banners allows Exploiting Incorrectly Configure...
CVE-2025-25117MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Polonski Smar...
CVE-2025-25111MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Cross Site Reques...
CVE-2025-25110MEDIUM5.4Missing Authorization vulnerability in Metagauss Event Kikfyre kikfyre-events-calendar-tickets allows Exploiting Incorre...
CVE-2025-25105MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in coffeestudios Pop ...
CVE-2025-25103MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in bnielsen Indeed API indeed-api allows Cross Site Request Forgery.This...
CVE-2025-25098MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz Links in...
CVE-2025-25097MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kwiliarty External...
CVE-2025-25096MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titusbicknell RSS ...
CVE-2025-25095MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reverbnationdev Re...
CVE-2025-25094MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amitythemes.com Br...
CVE-2025-25093MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in paulswarthout Child Themes Helper child-themes-helper allows Path Tra...
CVE-2025-25091MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zackdesign NextGen...
CVE-2025-25085MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matt_mcbrien WP Si...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now