2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13443MEDIUM6.5A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /...
CVE-2025-12778MEDIUM5.3The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-12502MEDIUM6.8The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL sta...
CVE-2025-13415MEDIUM5.4A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php...
CVE-2025-58181MEDIUM5.3SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, al...
CVE-2025-47914MEDIUM5.3SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the progra...
CVE-2025-13412MEDIUM6.1A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unkn...
CVE-2025-13147MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before ...
CVE-2025-63214MEDIUM6.5An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauth...
CVE-2025-63212MEDIUM6.5GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensiti...
CVE-2025-51662MEDIUM5.4A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and ea...
CVE-2025-36371MEDIUM6.5IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache impl...
CVE-2025-65100MEDIUM6.9Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT...
CVE-2025-64759MEDIUM6.1Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of ...
CVE-2025-63211MEDIUM6.1Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5...
CVE-2025-65089MEDIUM6.5XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to ver...
CVE-2025-65032MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ...
CVE-2025-65031MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in th...
CVE-2025-65028MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ...
CVE-2025-65020MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ...
CVE-2025-65019MEDIUM6.1Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with outp...
CVE-2025-64765MEDIUM5.3Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for rout...
CVE-2025-64764MEDIUM5.4Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feat...
CVE-2025-64708MEDIUM5.3authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions,...
CVE-2025-64521MEDIUM4.8authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now