2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12760MEDIUM5.4Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.T...
CVE-2025-9977MEDIUM5.3Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not saniti...
CVE-2025-64996MEDIUM4.4In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates worl...
CVE-2025-63604MEDIUM6.5A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code executi...
CVE-2025-63603MEDIUM6.5A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) ...
CVE-2025-58122MEDIUM5.4Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notifi...
CVE-2025-58121MEDIUM5.4Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4....
CVE-2025-8084MEDIUM6.8The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3....
CVE-2025-63892MEDIUM6.8A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_c...
CVE-2025-63883MEDIUM5.4A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client...
CVE-2025-59117MEDIUM4.8Windu CMS is vulnerable to multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the page editing endpoint windu...
CVE-2025-59116MEDIUM5.3Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow ...
CVE-2025-59115MEDIUM5.4Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation...
CVE-2025-59114MEDIUM6.5Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft spec...
CVE-2025-59112MEDIUM6.5Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft specia...
CVE-2025-59111MEDIUM6.5Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET reques...
CVE-2025-59110MEDIUM6.5Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechani...
CVE-2025-55179MEDIUM5.4Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.2...
CVE-2025-13349MEDIUM5.4A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown p...
CVE-2025-12545MEDIUM5.3The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is...
CVE-2025-12376MEDIUM6.4The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request ...
CVE-2025-10158MEDIUM4.3A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based bu...
CVE-2025-41350MEDIUM5.4Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store...
CVE-2025-41349MEDIUM5.4Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store...
CVE-2025-13343MEDIUM5.4A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now