2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13861MEDIUM6.1The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scriptin...
CVE-2025-11775MEDIUM4.8An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by ...
CVE-2025-13977MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2025-14801MEDIUM4.8A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of th...
CVE-2025-11369MEDIUM4.3The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unau...
CVE-2025-11009MEDIUM5.1Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all vers...
CVE-2025-34288MEDIUM6.7Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between s...
CVE-2025-64520MEDIUM4.3GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unau...
CVE-2025-14466MEDIUM6.9A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthe...
CVE-2025-13532MEDIUM6.2Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the sele...
CVE-2025-68150MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2025-68146MEDIUM6.5filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTO...
CVE-2025-65592MEDIUM6.1nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloa...
CVE-2025-65591MEDIUM5.4nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.
CVE-2025-65590MEDIUM5.4nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Managemen...
CVE-2025-68142MEDIUM5.3PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a R...
CVE-2025-65589MEDIUM6.1nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.
CVE-2025-65581MEDIUM5.3An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improp...
CVE-2025-46296MEDIUM5.4An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privile...
CVE-2025-46294MEDIUM5.3To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumerat...
CVE-2025-68116MEDIUM5.4FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site ...
CVE-2025-62862MEDIUM4.6Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4....
CVE-2025-59935MEDIUM6.5GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an una...
CVE-2025-29231MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers...
CVE-2025-68269MEDIUM5.4In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now