2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-27852MEDIUM5The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack...
CVE-2025-32425MEDIUM5.5AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...
CVE-2025-29338MEDIUM5.6NXP moal.ko Wi-Fi driver 5.1.7.10 FW version from v17.92.1.p149.43 To v17.92.1.p149.157 was discovered to contain a buff...
CVE-2025-14767MEDIUM5.5The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text...
CVE-2025-14033MEDIUM5.3The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mi...
CVE-2025-9989MEDIUM4.4The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2025-9988MEDIUM4.3The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat...
CVE-2025-9987MEDIUM5.3The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2025-14755MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct...
CVE-2025-61971MEDIUM5.9Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf...
CVE-2025-15463MEDIUM6.5The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all vers...
CVE-2025-67604MEDIUM5.3A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0...
CVE-2025-53870MEDIUM6.7An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2025-53680MEDIUM6.7An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vul...
CVE-2025-36515MEDIUM5.4Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may...
CVE-2025-36510MEDIUM6.8Improper buffer restrictions for some Display Virtualization for Windows OS driver software within Ring 2: Device Driver...
CVE-2025-35991MEDIUM5.6Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an informat...
CVE-2025-35979MEDIUM6.8Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient executio...
CVE-2025-35969MEDIUM5.4Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3...
CVE-2025-27723MEDIUM6.8Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Ke...
CVE-2025-70842MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The f...
CVE-2025-40948MEDIUM6.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-65417MEDIUM6.1docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page...
CVE-2025-65416MEDIUM6.3docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.
CVE-2025-65415MEDIUM5.4docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now