2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12494MEDIUM4.3The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insu...
CVE-2025-12182MEDIUM4.3The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize...
CVE-2025-13186MEDIUM5.4A weakness has been identified in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution up to 4.0. This ...
CVE-2025-64084MEDIUM5.4An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in app...
CVE-2025-63745MEDIUM5.5A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_n...
CVE-2025-63744MEDIUM4.3A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_d...
CVE-2025-13182MEDIUM4.8A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/...
CVE-2025-63701MEDIUM6.8A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.2078...
CVE-2025-13181MEDIUM4.8A vulnerability was determined in pojoin h3blog 1.0. The affected element is an unknown function of the file /admin/cms/...
CVE-2025-13180MEDIUM5.4A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 2025032...
CVE-2025-13179MEDIUM6.5A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20...
CVE-2025-63291MEDIUM5.4When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify ...
CVE-2025-13178MEDIUM5.4A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file ...
CVE-2025-13174MEDIUM6.3A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this vulnerability is the function d...
CVE-2025-63830MEDIUM6.1CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted...
CVE-2025-63725MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php.
CVE-2025-63724MEDIUM6SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php.
CVE-2025-54562MEDIUM4.3A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows ...
CVE-2025-54561MEDIUM4.3An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1...
CVE-2025-54348MEDIUM6.5A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version...
CVE-2025-54340MEDIUM4.1A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a B...
CVE-2025-4618MEDIUM4.4A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated no...
CVE-2025-8870MEDIUM5.6On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the devic...
CVE-2025-12149MEDIUM6In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, whe...
CVE-2025-10018MEDIUM4.8QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now