2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-66550MEDIUM5.7Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar ...
CVE-2025-66547MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-...
CVE-2025-66512MEDIUM6.1Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and ...
CVE-2025-66511MEDIUM6.5Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for me...
CVE-2025-66510MEDIUM4.9Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud E...
CVE-2025-14104MEDIUM6.1A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, spe...
CVE-2025-64056MEDIUM4.3File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbit...
CVE-2025-64052MEDIUM5.1An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arb...
CVE-2025-14089MEDIUM6.3A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the fil...
CVE-2025-14088MEDIUM6.3A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of...
CVE-2025-6966MEDIUM5.5NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause ...
CVE-2025-66200MEDIUM5.4mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the R...
CVE-2025-65082MEDIUM6.5Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment va...
CVE-2025-13620MEDIUM5.3The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions ...
CVE-2025-13739MEDIUM6.4The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all ...
CVE-2025-13682MEDIUM4.4The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u...
CVE-2025-13678MEDIUM6.4The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcod...
CVE-2025-12876MEDIUM5.3The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2025-13684MEDIUM4.3The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to m...
CVE-2025-12130MEDIUM4.3The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to...
CVE-2025-13515MEDIUM6.1The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF...
CVE-2025-12373MEDIUM4.3The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross...
CVE-2025-12355MEDIUM5.3The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ...
CVE-2025-12354MEDIUM4.3The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2025-12186MEDIUM4.4The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now