2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13589MEDIUM5.1FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthentica...
CVE-2025-13577MEDIUM5.4A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the fil...
CVE-2025-12800MEDIUM6.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all ...
CVE-2025-13566MEDIUM4.8A security vulnerability has been detected in jarun nnn up to 5.1. The impacted element is the function show_content_in_...
CVE-2025-13318MEDIUM5.3The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and...
CVE-2025-13136MEDIUM4.3The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-13317MEDIUM5.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ...
CVE-2025-12877MEDIUM5.3The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized mod...
CVE-2025-12752MEDIUM5.3The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions u...
CVE-2025-11186MEDIUM6.4The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-12889MEDIUM5.4With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those ...
CVE-2025-11936MEDIUM5.3Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote u...
CVE-2025-11933MEDIUM6.5Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows...
CVE-2025-11932MEDIUM4.3The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak info...
CVE-2025-65111MEDIUM5.3SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to ...
CVE-2025-65107MEDIUM6.5Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from...
CVE-2025-65092MEDIUM6.9ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the E...
CVE-2025-43374MEDIUM4.3An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad...
CVE-2025-31266MEDIUM4.3A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is f...
CVE-2025-31248MEDIUM5.5A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m...
CVE-2025-0504MEDIUM5.4Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with th...
CVE-2025-36149MEDIUM5.4IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim.
CVE-2025-13524MEDIUM6.8Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linu...
CVE-2025-64169MEDIUM4.9Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to befo...
CVE-2025-54866MEDIUM5.5Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to befo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now