2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7623MEDIUM5.4Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a s...
CVE-2025-12524MEDIUM5.4The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inc...
CVE-2025-52578MEDIUM5.7Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a soph...
CVE-2025-52457MEDIUM5.7Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an attacker with physical access to the device to extr...
CVE-2025-7711MEDIUM5.4The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary ...
CVE-2025-64766MEDIUM5.3NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and man...
CVE-2025-36299MEDIUM4.3IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further a...
CVE-2025-64758MEDIUM4.8@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis...
CVE-2025-64342MEDIUM6.9ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it re...
CVE-2025-55059MEDIUM6.1CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55056MEDIUM6.1Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-63918MEDIUM6.2PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attacker...
CVE-2025-13193MEDIUM5.5A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, ma...
CVE-2025-64046MEDIUM6.1OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
CVE-2025-63708MEDIUM6.1Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows re...
CVE-2025-40834MEDIUM6.8A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not prope...
CVE-2025-11681MEDIUM6.5Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2...
CVE-2025-13275MEDIUM4.7A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043...
CVE-2025-13268MEDIUM6.3A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/...
CVE-2025-13164MEDIUM6.9EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote a...
CVE-2025-13163MEDIUM6.9EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote a...
CVE-2025-60022MEDIUM4.8Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerabilit...
CVE-2025-13266MEDIUM5.5A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the f...
CVE-2025-13261MEDIUM5.3A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the fil...
CVE-2025-13249MEDIUM6.3A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /Off...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now