2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-26744MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog...
CVE-2025-26743HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Advance WP Qu...
CVE-2025-26741HIGH8.8Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Pri...
CVE-2025-32943MEDIUM4.3The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server...
CVE-2025-1688MEDIUM5.5Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configurati...
CVE-2025-2083MEDIUM6.4The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sliderId’ p...
CVE-2025-3579CRITICAL9.3In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute una...
CVE-2025-3578CRITICAL9.3A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify...
CVE-2025-3575HIGH8.7Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive infor...
CVE-2025-3574HIGH8.7Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive infor...
CVE-2025-3622MEDIUM5.5A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects t...
CVE-2025-3576MEDIUM5.9A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due...
CVE-2025-32993MEDIUM6.5Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-...
CVE-2025-2225MEDIUM5.4The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne...
CVE-2025-3573MEDIUM6.1Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() ...
CVE-2025-29984HIGH7.3Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privilege...
CVE-2025-29983HIGH7.3Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following'...
CVE-2025-3613MEDIUM5.1A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unkn...
CVE-2025-3612MEDIUM5.3A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part...
CVE-2025-3470MEDIUM4.9The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s ...
CVE-2025-32997MEDIUM5.3In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.
CVE-2025-32996MEDIUM5.3In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.
CVE-2025-32941Rejected reason: Not used
CVE-2025-32940Rejected reason: Not used
CVE-2025-32939Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now