2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14760MEDIUM6Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro...
CVE-2025-14759MEDIUM6Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to t...
CVE-2025-67173MEDIUM6.8A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrar...
CVE-2025-67170MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the...
CVE-2025-67168MEDIUM5.3RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
CVE-2025-14081MEDIUM4.3The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl...
CVE-2025-13537MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scri...
CVE-2025-13217MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for W...
CVE-2025-12689MEDIUM6.5Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for p...
CVE-2025-66924MEDIUM6.1A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remot...
CVE-2025-65855MEDIUM6.6The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-...
CVE-2025-26381MEDIUM6.5Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive informati...
CVE-2025-62690MEDIUM6.1Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to re...
CVE-2025-62190MEDIUM4.3Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail...
CVE-2025-14095MEDIUM6.8A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of thi...
CVE-2025-14347MEDIUM6.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-14399MEDIUM4.3The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2025-12496MEDIUM4.9The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin...
CVE-2025-14817MEDIUM6.5The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission contro...
CVE-2025-14061MEDIUM5.3The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C...
CVE-2025-13750MEDIUM4.3The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modif...
CVE-2025-14154MEDIUM6.1The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2025-64700MEDIUM5.1Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logg...
CVE-2025-14385MEDIUM6.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all ve...
CVE-2025-13880MEDIUM6.5The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now