2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15052MEDIUM5.4A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of...
CVE-2025-14421MEDIUM5.5pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allo...
CVE-2025-14411MEDIUM5.5Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem...
CVE-2025-14410MEDIUM5.5Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem...
CVE-2025-14407MEDIUM5.5Soda PDF Desktop PDF File Parsing Memory Corruption Information Disclosure Vulnerability. This vulnerability allows remo...
CVE-2025-14405MEDIUM6.8PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phy...
CVE-2025-13698MEDIUM4.5Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability a...
CVE-2025-65713MEDIUM4Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully val...
CVE-2025-65410MEDIUM6.2A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-45493MEDIUM6.5Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.
CVE-2025-68340MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of te...
CVE-2025-66845MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoin...
CVE-2025-68559MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem...
CVE-2025-68557MEDIUM4.3Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Acc...
CVE-2025-68556MEDIUM5.3Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect...
CVE-2025-68551MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form...
CVE-2025-68548MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Res...
CVE-2025-14635MEDIUM6.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom...
CVE-2025-14000MEDIUM6.4The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2025-14548MEDIUM6.4The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all ver...
CVE-2025-14163MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-14155MEDIUM5.3The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthor...
CVE-2025-67743MEDIUM6.5Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1...
CVE-2025-68614MEDIUM5.4LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule A...
CVE-2025-68480MEDIUM5.3Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions fro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now