2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-68512MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativeinteractiv...
CVE-2025-68511MEDIUM6.5Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configure...
CVE-2025-68509MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-post...
CVE-2025-68508MEDIUM5.3Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access C...
CVE-2025-68505MEDIUM5.3Missing Authorization vulnerability in icc0rz H5P h5p allows Exploiting Incorrectly Configured Access Control Security L...
CVE-2025-68500MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-l...
CVE-2025-68497MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force A...
CVE-2025-68494MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for El...
CVE-2025-67633MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brownbagmarketing ...
CVE-2025-67632MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Plugin Factory...
CVE-2025-67631MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecommerce Platform...
CVE-2025-67630MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webheadcoder WH Tw...
CVE-2025-67629MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basticom Basticom ...
CVE-2025-67628MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AMP-MODE Review Di...
CVE-2025-67627MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TouchOfTech Draft ...
CVE-2025-67625MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in tmtraderunner Trade Runner traderunner allows Cross Site Request Forg...
CVE-2025-67623MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Reques...
CVE-2025-67621MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in 10up Eight Day Week Print Wo...
CVE-2025-68725MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Do not let BPF test infra emit invalid GSO typ...
CVE-2025-68365MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use K...
CVE-2025-68358MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix racy bitfield write in btrfs_clear_space...
CVE-2025-68351MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: exfat: fix refcount leak in exfat_find Fix refcoun...
CVE-2025-64641MEDIUM4.1Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post ...
CVE-2025-13767MEDIUM4.3Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user ch...
CVE-2025-13407MEDIUM6.8The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files throug...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now