2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11991MEDIUM5.3The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2025-62330MEDIUM5.9HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains acce...
CVE-2025-13794MEDIUM4.3The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data du...
CVE-2025-12809MEDIUM5.3The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the...
CVE-2025-66357MEDIUM6.9CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. When the...
CVE-2025-59479MEDIUM6.1CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a use...
CVE-2025-14777MEDIUM6A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for author...
CVE-2025-13956MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
CVE-2025-14748MEDIUM5.4A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_...
CVE-2025-14747MEDIUM6.5A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTS...
CVE-2025-14746MEDIUM6.5A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the componen...
CVE-2025-68115MEDIUM6.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio...
CVE-2025-68113MEDIUM6.5ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA librari...
CVE-2025-67874MEDIUM6.5ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext pass...
CVE-2025-67735MEDIUM6.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final...
CVE-2025-67715MEDIUM4.3Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification setti...
CVE-2025-67492MEDIUM5.3Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for m...
CVE-2025-14758MEDIUM6.5Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows ...
CVE-2025-66482MEDIUM6.5Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a ...
CVE-2025-66407MEDIUM5Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add n...
CVE-2025-66402MEDIUM6.5Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025...
CVE-2025-9122MEDIUM5.3Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, includi...
CVE-2025-67809MEDIUM4.7An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present i...
CVE-2025-36360MEDIUM5IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM De...
CVE-2025-14148MEDIUM6.5IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration pri...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now