2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13751MEDIUM5.5Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a loc...
CVE-2025-7044MEDIUM6.5An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged ...
CVE-2025-57202MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 Full...
CVE-2025-57200MEDIUM6.5AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec...
CVE-2025-13949MEDIUM6.3A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /serv...
CVE-2025-13948MEDIUM5.6A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the ...
CVE-2025-13756MEDIUM4.3The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing ca...
CVE-2025-13401MEDIUM6.4The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox i...
CVE-2025-13359MEDIUM6.5The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL...
CVE-2025-13354MEDIUM4.3The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization ...
CVE-2025-13109MEDIUM4.3The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Re...
CVE-2025-12887MEDIUM5.4The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. Th...
CVE-2025-12358MEDIUM4.3The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2025-39665MEDIUM5.3User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate ...
CVE-2025-29864MEDIUM6.2Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZi...
CVE-2025-13472MEDIUM5.3A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of...
CVE-2025-13946MEDIUM5.5MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service
CVE-2025-13945MEDIUM5.5HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
CVE-2025-13495MEDIUM4.9The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, a...
CVE-2025-12585MEDIUM5.3The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio...
CVE-2025-10304MEDIUM5.3The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u...
CVE-2025-13646MEDIUM6.6The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2025-13448MEDIUM6.4The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode ...
CVE-2025-65955MEDIUM6.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9....
CVE-2025-55181MEDIUM5.3Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now