2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62761MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledg...
CVE-2025-62760MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPres...
CVE-2025-62759MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Ser...
CVE-2025-62758MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Funnelforms Funnel...
CVE-2025-62146MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Ti...
CVE-2025-62137MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shuttlethemes Shut...
CVE-2025-62136MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thinkupthemes Melo...
CVE-2025-14783MEDIUM4.3The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and includi...
CVE-2025-69277MEDIUM4.5libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_e...
CVE-2025-14434MEDIUM5.3The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints su...
CVE-2025-15374MEDIUM5.4A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application...
CVE-2025-15373MEDIUM4.3A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file appli...
CVE-2025-15372MEDIUM4.8A weakness has been identified in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing ...
CVE-2025-15223MEDIUM6.1A vulnerability was found in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. Impacted is an u...
CVE-2025-15112MEDIUM5.4Ksenia Security lares (legacy model) version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that...
CVE-2025-14987MEDIUM5.3When system.enableCrossNamespaceCommands is enabled (on by default), the Temporal server permits certain workflow task c...
CVE-2025-69257MEDIUM6.7theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to versi...
CVE-2025-69210MEDIUM5.4FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cr...
CVE-2025-66823MEDIUM5.4An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to...
CVE-2025-15258MEDIUM6.1A weakness has been identified in Edimax BR-6208AC 1.02/1.03. Affected by this issue is the function formALGSetup of the...
CVE-2025-68950MEDIUM6.2ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12...
CVE-2025-66103MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx WPCal.io w...
CVE-2025-66094MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dmccan Yada Wiki y...
CVE-2025-65925MEDIUM6.5An issue was discovered in Zeroheight (SaaS) prior to 2025-06-13. A legacy user creation API pathway allowed accounts to...
CVE-2025-62128MEDIUM4.3Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans siteloc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now