2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13353MEDIUM5.5In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely f...
CVE-2025-13873MEDIUM5.4Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application a...
CVE-2025-13870MEDIUM4.3Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files ...
CVE-2025-10543MEDIUM5.3In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library,...
CVE-2025-13696MEDIUM5.3The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6....
CVE-2025-11726MEDIUM4.3The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions ...
CVE-2025-13685MEDIUM4.3The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-13140MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-13007MEDIUM6.1The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets plugin for WordPress is vulnerable to Stored Cr...
CVE-2025-12483MEDIUM6.5The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'que...
CVE-2025-13001MEDIUM4.1The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, a...
CVE-2025-13606MEDIUM6.5The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2025-20792MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2025-20791MEDIUM6.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,...
CVE-2025-20790MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2025-20789MEDIUM4.4In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could lead to local informat...
CVE-2025-20788MEDIUM4.4In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of...
CVE-2025-20777MEDIUM6.7In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2025-20776MEDIUM6.7In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of...
CVE-2025-20775MEDIUM6.7In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2025-20774MEDIUM6.7In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o...
CVE-2025-20773MEDIUM6.7In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2025-20772MEDIUM6.7In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...
CVE-2025-20771MEDIUM6.7In display, there is a possible escalation of privilege due to improper input validation. This could lead to local escal...
CVE-2025-20770MEDIUM6.7In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now