2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-33192MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read...
CVE-2025-33191MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read....
CVE-2025-64061MEDIUM4.3Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access con...
CVE-2025-64049MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote ...
CVE-2025-13467MEDIUM5.5A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm adminis...
CVE-2025-59485MEDIUM4.8Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerabili...
CVE-2025-59372MEDIUM6.9A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could expl...
CVE-2025-59369MEDIUM5.9A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnera...
CVE-2025-59368MEDIUM6An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerabil...
CVE-2025-59365MEDIUM6.9A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigge...
CVE-2025-13452MEDIUM4.3The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Au...
CVE-2025-13414MEDIUM5.3The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing...
CVE-2025-13405MEDIUM5.3The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing aut...
CVE-2025-13404MEDIUM5.3The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing author...
CVE-2025-13389MEDIUM5.3The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthoriz...
CVE-2025-13386MEDIUM5.3The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2025-13385MEDIUM4.9The Bookme – Free Online Appointment Booking and Scheduling Plugin for WordPress is vulnerable to time-based SQL Injecti...
CVE-2025-13383MEDIUM6.1The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an...
CVE-2025-13382MEDIUM4.3The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2025-13380MEDIUM6.5The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in...
CVE-2025-13370MEDIUM4.9The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up...
CVE-2025-13311MEDIUM4.4The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting i...
CVE-2025-12645MEDIUM6.4The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortcod...
CVE-2025-12634MEDIUM4.3The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2025-12587MEDIUM4.3The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now