2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12666MEDIUM6.4The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin...
CVE-2025-12649MEDIUM6.4The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sortt...
CVE-2025-12579MEDIUM5.3The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2025-12578MEDIUM4.3The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-66030MEDIUM5.3Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overfl...
CVE-2025-7449MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18...
CVE-2025-6195MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6...
CVE-2025-65670MEDIUM4.3An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpo...
CVE-2025-13611MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 tha...
CVE-2025-12653MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 1...
CVE-2025-65676MEDIUM5.4Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi...
CVE-2025-65675MEDIUM5.4Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi...
CVE-2025-65239MEDIUM4.3Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13....
CVE-2025-65238MEDIUM6.5Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6....
CVE-2025-65237MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to e...
CVE-2025-63938MEDIUM6.5Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs....
CVE-2025-9191MEDIUM6.3The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via des...
CVE-2025-9163MEDIUM6.1The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ...
CVE-2025-13674MEDIUM5.5BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
CVE-2025-62728MEDIUM5.4SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thr...
CVE-2025-59820MEDIUM6.7In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex...
CVE-2025-66026MEDIUM6.1REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the M...
CVE-2025-66025MEDIUM4.3Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page i...
CVE-2025-66021MEDIUM6.1OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by thir...
CVE-2025-12848MEDIUM6.1Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now