2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64270MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in masteriyo Masteriyo - LMS le...
CVE-2025-64225MEDIUM6.5Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Stockie Extra st...
CVE-2025-64192MEDIUM6.3Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2025-63039MEDIUM6.5Missing Authorization vulnerability in CridioStudio ListingPro listingpro allows Exploiting Incorrectly Configured Acces...
CVE-2025-60088MEDIUM6.5Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incor...
CVE-2025-60070MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This i...
CVE-2025-60068MEDIUM6.5Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code In...
CVE-2025-54748MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg ...
CVE-2025-54745MEDIUM6.5Missing Authorization vulnerability in miniOrange miniOrange's Google Authenticator miniorange-2-factor-authentication a...
CVE-2025-54743MEDIUM5.8Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly...
CVE-2025-54741MEDIUM6.5Missing Authorization vulnerability in Tyler Moore Super Blank super-blank allows Exploiting Incorrectly Configured Acce...
CVE-2025-49919MEDIUM5.8Insertion of Sensitive Information Into Sent Data vulnerability in DigitalME eRoom eroom-zoom-meetings-webinar allows Re...
CVE-2025-49918MEDIUM5.9Insertion of Sensitive Information Into Sent Data vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikboo...
CVE-2025-49914MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu ...
CVE-2025-49902MEDIUM6.5Missing Authorization vulnerability in A WP Life Login Page Customizer – Customizer Login Page, Admin Page, Custom Desig...
CVE-2025-49041MEDIUM6.5Missing Authorization vulnerability in The African Boss Get Cash get-cash allows Exploiting Incorrectly Configured Acces...
CVE-2025-14318MEDIUM4.3Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using W...
CVE-2025-13498MEDIUM4.3The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions ...
CVE-2025-12976MEDIUM6.4The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-10019MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email al...
CVE-2025-68463MEDIUM4.9Bio.Entrez in Biopython through 186 allows doctype XXE.
CVE-2025-47325MEDIUM5.5Information disclosure while processing system calls with invalid parameters.
CVE-2025-47319MEDIUM6.7Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
CVE-2025-68461MEDIUM6.1Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani...
CVE-2025-12885MEDIUM6.4The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now