2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12349MEDIUM5.3The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Auth...
CVE-2025-6251MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['fi...
CVE-2025-12777MEDIUM5.3The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl...
CVE-2025-12770MEDIUM5.3The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and inclu...
CVE-2025-12427MEDIUM5.3The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ...
CVE-2025-13225MEDIUM6Tanium addressed an arbitrary file deletion vulnerability in TanOS.
CVE-2025-65093MEDIUM5.5LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based ...
CVE-2025-65013MEDIUM6.1LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cros...
CVE-2025-65012MEDIUM5.4Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any...
CVE-2025-64515MEDIUM4.3Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data ...
CVE-2025-54990MEDIUM5.3XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users with...
CVE-2025-63229MEDIUM5.4The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting ...
CVE-2025-63226MEDIUM5.7The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking...
CVE-2025-63749MEDIUM6.5pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.
CVE-2025-63693MEDIUM5.4The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping fo...
CVE-2025-61664MEDIUM4.9A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free iss...
CVE-2025-61663MEDIUM4.9A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (...
CVE-2025-61661MEDIUM4.8A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootl...
CVE-2025-56499MEDIUM6.5Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary f...
CVE-2025-54771MEDIUM4.9A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because t...
CVE-2025-54770MEDIUM4.9A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (...
CVE-2025-54320MEDIUM4.3In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email ...
CVE-2025-52639MEDIUM6.5HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sen...
CVE-2025-37160MEDIUM6.5A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote at...
CVE-2025-37156MEDIUM6.8A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now