2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65020MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ...
CVE-2025-65019MEDIUM6.1Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with outp...
CVE-2025-64765MEDIUM5.3Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for rout...
CVE-2025-64764MEDIUM5.4Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feat...
CVE-2025-64708MEDIUM5.3authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions,...
CVE-2025-64521MEDIUM4.8authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client...
CVE-2025-34336MEDIUM6.9eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vuln...
CVE-2025-34330MEDIUM5.3AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration...
CVE-2025-12766MEDIUM5An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) versio...
CVE-2025-12743MEDIUM6The Looker endpoint for generating new projects from database connections allows users to specify "looker" as a connecti...
CVE-2025-63879MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 ...
CVE-2025-63878MEDIUM6.5Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form pag...
CVE-2025-13397MEDIUM5.5A security vulnerability has been detected in mrubyc up to 3.4. This impacts the function mrbc_raw_realloc of the file s...
CVE-2025-63243MEDIUM4.6A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25....
CVE-2025-11963MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Comp...
CVE-2025-0421MEDIUM4.7Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software Technologies Inc. Shopside allow...
CVE-2025-64408MEDIUM6.3Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controlla...
CVE-2025-58412MEDIUM6.1A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0...
CVE-2025-11446MEDIUM6.5Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know...
CVE-2025-13206MEDIUM6.1The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2025-13085MEDIUM4.3The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta...
CVE-2025-12535MEDIUM5.3The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and includi...
CVE-2025-13054MEDIUM6.4The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2025-12878MEDIUM6.4The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-12842MEDIUM5.3The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sendi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now