2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13877MEDIUM5.6A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the ...
CVE-2025-13372MEDIUM4.3An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to ...
CVE-2025-12630MEDIUM4.9The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability ch...
CVE-2025-59705MEDIUM6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker...
CVE-2025-59701MEDIUM4.1Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-59699MEDIUM6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-59698MEDIUM6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate at...
CVE-2025-59694MEDIUM6.8The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow...
CVE-2025-13875MEDIUM6.3A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file ...
CVE-2025-13505MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Neutralization of ...
CVE-2025-41086MEDIUM6.5Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be gener...
CVE-2025-41066MEDIUM5.3Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the ex...
CVE-2025-13731MEDIUM6.4The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-41012MEDIUM5.3Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attack...
CVE-2025-40700MEDIUM6.1Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScri...
CVE-2025-13090MEDIUM4.9The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up t...
CVE-2025-41743MEDIUM4Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unpriv...
CVE-2025-13353MEDIUM5.5In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely f...
CVE-2025-13873MEDIUM5.4Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application a...
CVE-2025-13870MEDIUM4.3Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files ...
CVE-2025-10543MEDIUM5.3In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library,...
CVE-2025-13696MEDIUM5.3The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6....
CVE-2025-11726MEDIUM4.3The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions ...
CVE-2025-13685MEDIUM4.3The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-13140MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now