2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13945MEDIUM5.5HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
CVE-2025-13495MEDIUM4.9The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, a...
CVE-2025-12585MEDIUM5.3The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio...
CVE-2025-10304MEDIUM5.3The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u...
CVE-2025-13646MEDIUM6.6The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2025-13448MEDIUM6.4The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode ...
CVE-2025-65955MEDIUM6.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9....
CVE-2025-55181MEDIUM5.3Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuic...
CVE-2025-65657MEDIUM6.5FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1...
CVE-2025-65380MEDIUM6.5PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username...
CVE-2025-65379MEDIUM6.5PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically,...
CVE-2025-66468MEDIUM6.1The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior ...
CVE-2025-66460MEDIUM6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-66459MEDIUM6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-66458MEDIUM6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-66454MEDIUM6.5Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a har...
CVE-2025-57850MEDIUM6.4A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/p...
CVE-2025-13637MEDIUM4.3Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convince...
CVE-2025-13636MEDIUM4.3Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinc...
CVE-2025-13635MEDIUM4.4Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI...
CVE-2025-13634MEDIUM4.4Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to...
CVE-2025-13632MEDIUM5.4Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a use...
CVE-2025-65881MEDIUM6.1Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php.
CVE-2025-65215MEDIUM6.1Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product...
CVE-2025-65105MEDIUM5.3Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now