2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15441MEDIUM6.8The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" ...
CVE-2025-66447MEDIUM4.7Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through ...
CVE-2025-14545MEDIUM6.5The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation ...
CVE-2025-70797MEDIUM6.1Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via...
CVE-2025-63238MEDIUM6.1A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validatio...
CVE-2025-70365MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-sup...
CVE-2025-70811MEDIUM4.3Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t...
CVE-2025-45806MEDIUM6.1A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrar...
CVE-2025-9484MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.1...
CVE-2025-57175MEDIUM6.8Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.
CVE-2025-14243MEDIUM5.3A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enum...
CVE-2025-58713MEDIUM6.4A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f...
CVE-2025-57854MEDIUM6.4A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from...
CVE-2025-57853MEDIUM6.4A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi...
CVE-2025-57851MEDIUM6.7A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f...
CVE-2025-57847MEDIUM6.4A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th...
CVE-2025-1794MEDIUM5.4The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all vers...
CVE-2025-14732MEDIUM6.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-20628MEDIUM6.9An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) w...
CVE-2025-14858MEDIUM5.1The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability...
CVE-2025-14857MEDIUM5.4An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware ...
CVE-2025-70844MEDIUM6.1yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Acco...
CVE-2025-14944MEDIUM5.3The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2...
CVE-2025-24819MEDIUM5.7Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter...
CVE-2025-15611MEDIUM5.4The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function be...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now