2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53444MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This i...
CVE-2025-12141MEDIUM6.5In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif...
CVE-2025-52641MEDIUM5.3HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem str...
CVE-2025-15470MEDIUM6.5The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th...
CVE-2025-15565MEDIUM5.3The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization check...
CVE-2025-68649MEDIUM6.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyze...
CVE-2025-65136MEDIUM6.1In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php v...
CVE-2025-65134MEDIUM6.1In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms...
CVE-2025-65132MEDIUM6.1alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which a...
CVE-2025-61886MEDIUM5.4An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-61624MEDIUM6.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For...
CVE-2025-59809MEDIUM4.3A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR P...
CVE-2025-69993MEDIUM6.1Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This...
CVE-2025-69893MEDIUM4.6A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13...
CVE-2025-13822MEDIUM5.3MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authenticati...
CVE-2025-40745MEDIUM6.3A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V...
CVE-2025-70936MEDIUM5.4Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handl...
CVE-2025-63743MEDIUM5.4Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 a...
CVE-2025-15441MEDIUM6.8The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" ...
CVE-2025-66447MEDIUM4.7Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through ...
CVE-2025-14545MEDIUM6.5The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation ...
CVE-2025-70797MEDIUM6.1Cross Site Scripting vulnerability in Limesurvey v.6.15.20+251021 allows a remote attacker to execute arbitrary code via...
CVE-2025-63238MEDIUM6.1A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validatio...
CVE-2025-70365MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-sup...
CVE-2025-70811MEDIUM4.3Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now