2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-66051MEDIUM6.5Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated a...
CVE-2025-14172MEDIUM6.5The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i...
CVE-2025-13967MEDIUM6.4The Woodpecker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_name' param...
CVE-2025-13908MEDIUM6.4The The Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'the_tooltip' shortco...
CVE-2025-13903MEDIUM6.4The PullQuote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pullquote' shortcode i...
CVE-2025-13897MEDIUM6.4The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aft_testimonial...
CVE-2025-13893MEDIUM6.1The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`...
CVE-2025-13892MEDIUM6.1The MG AdvancedOptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'...
CVE-2025-13862MEDIUM6.4The Menu Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `category` parameter in all vers...
CVE-2025-13854MEDIUM6.4The Curved Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'radius' parameter of the arct...
CVE-2025-13852MEDIUM6.4The Debt.com Business in a Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configuration'...
CVE-2025-13717MEDIUM5.3The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa...
CVE-2025-13704MEDIUM6.4The Autogen Headers Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head_class' paramete...
CVE-2025-13701MEDIUM6.1The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] para...
CVE-2025-11453MEDIUM6.4The Header and Footer Scripts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _inpost_head_scr...
CVE-2025-9222MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and...
CVE-2025-13900MEDIUM6.4The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wp...
CVE-2025-13895MEDIUM6.1The Top Position Google Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['...
CVE-2025-13853MEDIUM6.4The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter o...
CVE-2025-13781MEDIUM6.5GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7...
CVE-2025-13772MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7...
CVE-2025-13729MEDIUM6.4The Entry Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'entry-views' shortco...
CVE-2025-11246MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 1...
CVE-2025-10569MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18...
CVE-2025-14146MEDIUM5.3The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now