2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-52186MEDIUM6.5Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery ...
CVE-2025-13120MEDIUM5.5A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/ar...
CVE-2025-64738MEDIUM5.5External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user ...
CVE-2025-62482MEDIUM6.1Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact int...
CVE-2025-30669MEDIUM6.5Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of inf...
CVE-2025-30662MEDIUM6.5Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6....
CVE-2025-13119MEDIUM6.5A flaw has been found in Fabian Ros/SourceCodester Simple E-Banking System 1.0. This affects an unknown part. This manip...
CVE-2025-13118MEDIUM4.3A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of ...
CVE-2025-13117MEDIUM5.3A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability...
CVE-2025-41069MEDIUM5.3Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to...
CVE-2025-13116MEDIUM5.3A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder o...
CVE-2025-13115MEDIUM5.3A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of t...
CVE-2025-13114MEDIUM5.3A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /c...
CVE-2025-40681MEDIUM5.1Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker...
CVE-2025-12818MEDIUM5.9Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network...
CVE-2025-12377MEDIUM4.3The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2025-7704MEDIUM5.4Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability
CVE-2025-64384MEDIUM5.3Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configure...
CVE-2025-64383MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-...
CVE-2025-64382MEDIUM4.3Missing Authorization vulnerability in WebToffee Order Export & Order Import for WooCommerce order-import-export-for-woo...
CVE-2025-64381MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking ...
CVE-2025-64380MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster f...
CVE-2025-64379MEDIUM4.3Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectl...
CVE-2025-64370MEDIUM5.3Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2025-64369MEDIUM6.5Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now