2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53444 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This i... |
| CVE-2025-12141 | MEDIUM | 6.5 | 0.3% | Apr 15, 2026 | In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif... |
| CVE-2025-52641 | MEDIUM | 5.3 | 0.1% | Apr 15, 2026 | HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str... |
| CVE-2025-15470 | MEDIUM | 6.5 | 0.3% | Apr 15, 2026 | The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th... |
| CVE-2025-15565 | MEDIUM | 5.3 | 0.2% | Apr 14, 2026 | The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization check... |
| CVE-2025-68649 | MEDIUM | 6.5 | 0.4% | Apr 14, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyze... |
| CVE-2025-65136 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php v... |
| CVE-2025-65134 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms... |
| CVE-2025-65132 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which a... |
| CVE-2025-61886 | MEDIUM | 5.4 | 0.3% | Apr 14, 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2025-61624 | MEDIUM | 6.5 | 0.5% | Apr 14, 2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For... |
| CVE-2025-59809 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR P... |
| CVE-2025-69993 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This... |
| CVE-2025-69893 | MEDIUM | 4.6 | 0.2% | Apr 14, 2026 | A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13... |
| CVE-2025-13822 | MEDIUM | 5.3 | 0.4% | Apr 14, 2026 | MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authenticati... |
| CVE-2025-40745 | MEDIUM | 6.3 | 0.1% | Apr 14, 2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V... |
| CVE-2025-70936 | MEDIUM | 5.4 | 0.1% | Apr 13, 2026 | Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handl... |
| CVE-2025-63743 | MEDIUM | 5.4 | 0.3% | Apr 13, 2026 | Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 a... |
| CVE-2025-15441 | MEDIUM | 6.8 | 0.3% | Apr 13, 2026 | The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" ... |
| CVE-2025-66447 | MEDIUM | 4.7 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through ... |
| CVE-2025-14545 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation ... |
| CVE-2025-70797 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via... |
| CVE-2025-63238 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validatio... |
| CVE-2025-70365 | MEDIUM | 5.4 | 0.1% | Apr 9, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-sup... |
| CVE-2025-70811 | MEDIUM | 4.3 | 0.1% | Apr 9, 2026 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now