2025 CVE Vulnerabilities

45,124 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15544MEDIUM5.9A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials assoc...
CVE-2025-9291MEDIUM6.5A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif...
CVE-2025-15673MEDIUM4.9The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an...
CVE-2025-15675MEDIUM4.8The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor...
CVE-2025-71404MEDIUM5.1better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ...
CVE-2025-14073MEDIUM5.3The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur...
CVE-2025-14469MEDIUM4.3The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-15669MEDIUM4.8The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren...
CVE-2025-62347MEDIUM4.3HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and...
CVE-2025-67651MEDIUM6.9A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF ...
CVE-2025-65342MEDIUM6.1code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.
CVE-2025-65341MEDIUM6.1Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.
CVE-2025-51684MEDIUM6.1CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data ...
CVE-2025-36374MEDIUM5.5IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile...
CVE-2025-0152MEDIUM6.1IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1...
CVE-2025-36431MEDIUM5.4IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera...
CVE-2025-36298MEDIUM5.4IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0...
CVE-2025-65337MEDIUM6.1Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address ...
CVE-2025-59181MEDIUM4.8Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio...
CVE-2025-59180MEDIUM5.1Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm s...
CVE-2025-59178MEDIUM4.8Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera...
CVE-2025-59177MEDIUM6.8Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowi...
CVE-2025-9205MEDIUM6.4The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14....
CVE-2025-68081MEDIUM5.9Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
CVE-2025-50325MEDIUM5.4BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now