2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10567MEDIUM6.3The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its check...
CVE-2025-11162MEDIUM6.4The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-12580MEDIUM6.1The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in ...
CVE-2025-11835MEDIUM5.3The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2025-8871MEDIUM5.6The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,...
CVE-2025-12582MEDIUM4.3The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2025-62722MEDIUM5.4LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functio...
CVE-2025-59596MEDIUM6.5CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addr...
CVE-2025-62721MEDIUM6.5LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints...
CVE-2025-62720MEDIUM6.5LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to expo...
CVE-2025-62719MEDIUM4.3LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function...
CVE-2025-62715MEDIUM5.4ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Script...
CVE-2025-62520MEDIUM4.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-...
CVE-2025-55155MEDIUM5.4Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their pro...
CVE-2025-54335MEDIUM6.5An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-afte...
CVE-2025-48884MEDIUM6.1Galette is a membership management web application for non profit organizations. In versions 1.1.5.2 and below, Galette'...
CVE-2025-48076MEDIUM5.4Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user...
CVE-2025-27374MEDIUM5.3An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 982...
CVE-2025-61431MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance ...
CVE-2025-54327MEDIUM6.5An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W...
CVE-2025-33176MEDIUM6.2NVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communicatio...
CVE-2025-64322MEDIUM5.3Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Mani...
CVE-2025-64321MEDIUM5.3Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Ma...
CVE-2025-64320MEDIUM6.5Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Co...
CVE-2025-64319MEDIUM5.3Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now