2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59491MEDIUM6.1Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields.
CVE-2025-59089MEDIUM5.9If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery...
CVE-2025-52331MEDIUM6.1Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to...
CVE-2025-9316MEDIUM6.9N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.
CVE-2025-11566MEDIUM6.9CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker on ...
CVE-2025-62876MEDIUM5.3A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to ...
CVE-2025-40164MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible...
CVE-2025-11454MEDIUM6.5The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable t...
CVE-2025-64407MEDIUM5.3Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att...
CVE-2025-61623MEDIUM6.5Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users ...
CVE-2025-37734MEDIUM4.3Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by t...
CVE-2025-64406MEDIUM4.3An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash t...
CVE-2025-64402MEDIUM6.5Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att...
CVE-2025-12732MEDIUM4.3The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sen...
CVE-2025-12872MEDIUM5.4The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote ...
CVE-2025-12869MEDIUM4.8The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administr...
CVE-2025-12113MEDIUM4.3The Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images plugin for WordPress is vulnerable to unaut...
CVE-2025-12018MEDIUM4.4The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2025-12901MEDIUM4.3The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-12833MEDIUM4.3The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2025-12087MEDIUM4.3The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference i...
CVE-2025-54983MEDIUM5.2A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under sp...
CVE-2025-43205MEDIUM4An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18...
CVE-2025-40760MEDIUM6.8A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly ...
CVE-2025-12748MEDIUM5.5A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files w...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now