2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14761MEDIUM6Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to intro...
CVE-2025-67074MEDIUM6.5A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot...
CVE-2025-65233MEDIUM6.1Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ...
CVE-2025-34440MEDIUM6.1AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedire...
CVE-2025-34439MEDIUM6.1AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri paramet...
CVE-2025-34435MEDIUM6.5AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated...
CVE-2025-14760MEDIUM6Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to intro...
CVE-2025-14759MEDIUM6Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to t...
CVE-2025-67173MEDIUM6.8A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrar...
CVE-2025-67170MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the...
CVE-2025-67168MEDIUM5.3RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
CVE-2025-14081MEDIUM4.3The Ultimate Member plugin for WordPress is vulnerable to Profile Privacy Setting Bypass in all versions up to, and incl...
CVE-2025-13537MEDIUM6.4The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scri...
CVE-2025-13217MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin for W...
CVE-2025-12689MEDIUM6.5Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for p...
CVE-2025-66924MEDIUM6.1A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remot...
CVE-2025-65855MEDIUM6.6The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-...
CVE-2025-26381MEDIUM6.5Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive informati...
CVE-2025-62690MEDIUM6.1Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to re...
CVE-2025-62190MEDIUM4.3Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail...
CVE-2025-14095MEDIUM6.8A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of thi...
CVE-2025-14347MEDIUM6.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft...
CVE-2025-14399MEDIUM4.3The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2025-12496MEDIUM4.9The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin...
CVE-2025-14817MEDIUM6.5The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission contro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now