2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13489MEDIUM5.9IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attac...
CVE-2025-12035MEDIUM6.5An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for proc...
CVE-2025-65835MEDIUM6.2The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an export...
CVE-2025-51962MEDIUM6.1A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attacker...
CVE-2025-66436MEDIUM4.3An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext t...
CVE-2025-66435MEDIUM4.3An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext thro...
CVE-2025-55901MEDIUM6.5TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_...
CVE-2025-55893MEDIUM6.5TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.
CVE-2025-66963MEDIUM5.5An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in...
CVE-2025-66843MEDIUM5.4grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An...
CVE-2025-14387MEDIUM6.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ...
CVE-2025-14003MEDIUM4.3The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2025-13950MEDIUM5.3The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2025-13728MEDIUM6.4The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored...
CVE-2025-13610MEDIUM6.4The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2025-13608MEDIUM6.4The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in ...
CVE-2025-13367MEDIUM6.4The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict...
CVE-2025-12900MEDIUM4.3The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorizatio...
CVE-2025-65782MEDIUM6.5An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization ...
CVE-2025-65431MEDIUM5.4An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the ident...
CVE-2025-65430MEDIUM5.4An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tok...
CVE-2025-66388MEDIUM6.5A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secr...
CVE-2025-37732MEDIUM5.4Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us...
CVE-2025-14714MEDIUM6.5An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the T...
CVE-2025-11670MEDIUM4.3Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is e...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now