2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54748MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg ...
CVE-2025-54745MEDIUM6.5Missing Authorization vulnerability in miniOrange miniOrange's Google Authenticator miniorange-2-factor-authentication a...
CVE-2025-54743MEDIUM5.8Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly...
CVE-2025-54741MEDIUM6.5Missing Authorization vulnerability in Tyler Moore Super Blank super-blank allows Exploiting Incorrectly Configured Acce...
CVE-2025-49919MEDIUM5.8Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Re...
CVE-2025-49918MEDIUM5.9Insertion of Sensitive Information Into Sent Data vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikboo...
CVE-2025-49914MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu ...
CVE-2025-49902MEDIUM6.5Missing Authorization vulnerability in A WP Life Login Page Customizer – Customizer Login Page, Admin Page, Custom Desig...
CVE-2025-49041MEDIUM6.5Missing Authorization vulnerability in The African Boss Get Cash get-cash allows Exploiting Incorrectly Configured Acces...
CVE-2025-14318MEDIUM4.3Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using W...
CVE-2025-13498MEDIUM4.3The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions ...
CVE-2025-12976MEDIUM6.4The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-10019MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email al...
CVE-2025-68463MEDIUM4.9Bio.Entrez in Biopython through 186 allows doctype XXE.
CVE-2025-47325MEDIUM5.5Information disclosure while processing system calls with invalid parameters.
CVE-2025-47319MEDIUM6.7Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
CVE-2025-68461MEDIUM6.1Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani...
CVE-2025-12885MEDIUM6.4The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-...
CVE-2025-68429MEDIUM5.3Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present ...
CVE-2025-68401MEDIUM4.8ChurchCRM is an open-source church management system. Prior to version 6.0.0, the application stores user-supplied HTML/...
CVE-2025-68399MEDIUM5.4ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting...
CVE-2025-68275MEDIUM4.8ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a stored cross-site scripting vulnera...
CVE-2025-67876MEDIUM5.4ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in Church...
CVE-2025-67875MEDIUM5.4ChurchCRM is an open-source church management system. A privilege escalation vulnerability exists in ChurchCRM prior to ...
CVE-2025-67794MEDIUM6.1An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and fi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now