2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-41104MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-41103MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-41102MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-41101MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-11960MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Softw...
CVE-2025-7633MEDIUM6.1Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t...
CVE-2025-7632MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t...
CVE-2025-7430MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t...
CVE-2025-12953MEDIUM4.3The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to una...
CVE-2025-12788MEDIUM5.3The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment veri...
CVE-2025-12787MEDIUM5.3The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking...
CVE-2025-9524MEDIUM4.3The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usabilit...
CVE-2025-9055MEDIUM6.4The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain L...
CVE-2025-7429MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t...
CVE-2025-5317MEDIUM5.5An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 a...
CVE-2025-8108MEDIUM6.7An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privileg...
CVE-2025-6779MEDIUM6.7An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privile...
CVE-2025-6571MEDIUM6A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.
CVE-2025-6298MEDIUM6.7ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escala...
CVE-2025-5718MEDIUM6.8The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be...
CVE-2025-5454MEDIUM6.7An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote...
CVE-2025-5452MEDIUM6.6A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applicat...
CVE-2025-4645MEDIUM6.7An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vuln...
CVE-2025-11237MEDIUM5.3The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option va...
CVE-2025-12880MEDIUM5.4The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now