2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12898MEDIUM5.3The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2025-12581MEDIUM6.1The Attachments Handler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up ...
CVE-2025-8065MEDIUM6.5A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6....
CVE-2025-14299MEDIUM6.5The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer over...
CVE-2025-67712MEDIUM4.7There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a re...
CVE-2025-12874MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Mana...
CVE-2025-14965MEDIUM5.5A vulnerability was found in 1541492390c yougou-mall up to 0a771fa817c924efe52c8fe0a9a6658eee675f9f. This impacts the fu...
CVE-2025-14962MEDIUM6.1A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file ...
CVE-2025-68430MEDIUM4.3CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.8.1 through 2.52.0...
CVE-2025-68477MEDIUM6.5Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides...
CVE-2025-68457MEDIUM6.1Orejime is a consent manager that focuses on accessibility. On HTML elements handled by Orejime prior to version 2.3.2, ...
CVE-2025-65035MEDIUM6.4pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the d...
CVE-2025-14957MEDIUM5.5A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBu...
CVE-2025-66906MEDIUM6.1Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows attackers to gain escala...
CVE-2025-53922MEDIUM4.9Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to ...
CVE-2025-14954MEDIUM5.9A vulnerability has been found in Open5GS up to 2.7.6. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_fi...
CVE-2025-14953MEDIUM5.3A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pf...
CVE-2025-66911MEDIUM6.5Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status qu...
CVE-2025-66910MEDIUM6Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authe...
CVE-2025-66908MEDIUM5.3Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR ...
CVE-2025-14946MEDIUM4.8A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Unifor...
CVE-2025-1885MEDIUM5.4URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food ...
CVE-2025-14455MEDIUM5.4The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up t...
CVE-2025-12361MEDIUM4.3The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulne...
CVE-2025-11747MEDIUM6.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts sh...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now