2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9122MEDIUM5.3Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, includi...
CVE-2025-67809MEDIUM4.7An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present i...
CVE-2025-36360MEDIUM5IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM De...
CVE-2025-14148MEDIUM6.5IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration pri...
CVE-2025-13489MEDIUM5.9IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attac...
CVE-2025-12035MEDIUM6.5An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for proc...
CVE-2025-65835MEDIUM6.2The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an export...
CVE-2025-51962MEDIUM6.1A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attacker...
CVE-2025-66436MEDIUM4.3An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext t...
CVE-2025-66435MEDIUM4.3An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext thro...
CVE-2025-55901MEDIUM6.5TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_...
CVE-2025-55893MEDIUM6.5TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.
CVE-2025-66963MEDIUM5.5An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in...
CVE-2025-66843MEDIUM5.4grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An...
CVE-2025-14387MEDIUM6.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ...
CVE-2025-14003MEDIUM4.3The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2025-13950MEDIUM5.3The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2025-13728MEDIUM6.4The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored...
CVE-2025-13610MEDIUM6.4The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2025-13608MEDIUM6.4The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in ...
CVE-2025-13367MEDIUM6.4The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict...
CVE-2025-12900MEDIUM4.3The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorizatio...
CVE-2025-65782MEDIUM6.5An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization ...
CVE-2025-65431MEDIUM5.4An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the ident...
CVE-2025-65430MEDIUM5.4An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tok...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now