2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-68161MEDIUM4.8The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of...
CVE-2025-63949MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remot...
CVE-2025-63948MEDIUM5.4A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute ar...
CVE-2025-63947MEDIUM5.4A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An ...
CVE-2025-59529MEDIUM5.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions...
CVE-2025-14848MEDIUM5.3Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the ex...
CVE-2025-67163MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary ...
CVE-2025-64400MEDIUM4.1Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. Th...
CVE-2025-14889MEDIUM6.3A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unkno...
CVE-2025-59949MEDIUM6.5FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vuln...
CVE-2025-14739MEDIUM6.8Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allows local unauthenticated attackers the a...
CVE-2025-66058MEDIUM6.5Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectl...
CVE-2025-64355MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem...
CVE-2025-64282MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in RadiusTheme Radius Blocks radius-blocks allows Exploit...
CVE-2025-64235MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows...
CVE-2025-63043MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid a...
CVE-2025-63002MEDIUM5.3Missing Authorization vulnerability in wpforchurch Sermon Manager sermon-manager-for-wordpress allows Exploiting Incorre...
CVE-2025-62998MEDIUM5Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Re...
CVE-2025-62961MEDIUM5.4Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured ...
CVE-2025-62960MEDIUM5.4Missing Authorization vulnerability in sparklewpthemes Construction Light construction-light allows Exploiting Incorrect...
CVE-2025-64723MEDIUM4.4Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with ...
CVE-2025-63390MEDIUM5.3An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fa...
CVE-2025-14823MEDIUM5.3In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure...
CVE-2025-9787MEDIUM6.1Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulne...
CVE-2025-7047MEDIUM5.4Missing Authorization vulnerability in Utarit Informatics Services Inc. SoliClub allows Privilege Abuse. This issue aff...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now