2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36579MEDIUM5.1Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph...
CVE-2025-15621MEDIUM5.7Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the re...
CVE-2025-12624MEDIUM5.4Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This fail...
CVE-2025-6024MEDIUM6.1The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script...
CVE-2025-13364MEDIUM6.4The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera...
CVE-2025-15636MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You...
CVE-2025-15635MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cro...
CVE-2025-53444MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This i...
CVE-2025-12141MEDIUM6.5In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif...
CVE-2025-52641MEDIUM5.3HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str...
CVE-2025-15470MEDIUM6.5The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th...
CVE-2025-15565MEDIUM5.3The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization check...
CVE-2025-68649MEDIUM6.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyze...
CVE-2025-65136MEDIUM6.1In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php v...
CVE-2025-65134MEDIUM6.1In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms...
CVE-2025-65132MEDIUM6.1alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which a...
CVE-2025-61886MEDIUM5.4An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-61624MEDIUM6.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For...
CVE-2025-59809MEDIUM4.3A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR P...
CVE-2025-69993MEDIUM6.1Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This...
CVE-2025-69893MEDIUM4.6A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13...
CVE-2025-13822MEDIUM5.3MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authenticati...
CVE-2025-40745MEDIUM6.3A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V...
CVE-2025-70936MEDIUM5.4Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handl...
CVE-2025-63743MEDIUM5.4Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now