2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65496MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-41017MEDIUM6.9Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve pers...
CVE-2025-12628MEDIUM6.3The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass th...
CVE-2025-41087MEDIUM5.1Cross-Site Scripting (XSS) vulnerability stored in tha Taclia web application, where the uploaded SVG images are not pro...
CVE-2025-13588MEDIUM6.3A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown fun...
CVE-2025-12569MEDIUM4.7The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before ...
CVE-2025-12394MEDIUM5.9The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configur...
CVE-2025-13589MEDIUM5.1FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthentica...
CVE-2025-13577MEDIUM5.4A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the fil...
CVE-2025-12800MEDIUM6.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all ...
CVE-2025-13566MEDIUM4.8A security vulnerability has been detected in jarun nnn up to 5.1. The impacted element is the function show_content_in_...
CVE-2025-13318MEDIUM5.3The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and...
CVE-2025-13136MEDIUM4.3The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-13317MEDIUM5.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ...
CVE-2025-12877MEDIUM5.3The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized mod...
CVE-2025-12752MEDIUM5.3The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions u...
CVE-2025-11186MEDIUM6.4The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-12889MEDIUM5.4With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those ...
CVE-2025-11936MEDIUM5.3Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote u...
CVE-2025-11933MEDIUM6.5Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows...
CVE-2025-11932MEDIUM4.3The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak info...
CVE-2025-65111MEDIUM5.3SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to ...
CVE-2025-65107MEDIUM6.5Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from...
CVE-2025-65092MEDIUM6.9ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the E...
CVE-2025-43374MEDIUM4.3An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now