2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10734MEDIUM5.3The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-10731MEDIUM5.3The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-10736MEDIUM6.5The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-71276MEDIUM6.1SOGo before 5.12.5 is prone to a XSS vulnerability with events, tasks, and contacts categories.
CVE-2025-13910MEDIUM6.1The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJA...
CVE-2025-63260MEDIUM5.4SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-U...
CVE-2025-62846MEDIUM6.7An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, th...
CVE-2025-62845MEDIUM6.7An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a l...
CVE-2025-62844MEDIUM5.5A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they c...
CVE-2025-62843MEDIUM6.8An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. ...
CVE-2025-46598MEDIUM5.3Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.
CVE-2025-67115MEDIUM6.5A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware befor...
CVE-2025-14716MEDIUM6.5Improper Authentication vulnerability in Secomea GateManager (webserver modules) allows Authentication Bypass.This issue...
CVE-2025-62043MEDIUM6.5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPSight WPCasa all...
CVE-2025-32223MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly ...
CVE-2025-36051MEDIUM5.5IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 stores potentially sensitive information in configuration files th...
CVE-2025-15051MEDIUM5.4IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2025-13995MEDIUM5IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 could allow an attacker with access to one tenant to access hostna...
CVE-2025-71270MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: Enable exception fixup for specific ADE ...
CVE-2025-71269MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback fro...
CVE-2025-71268MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths whe...
CVE-2025-55043MEDIUM6.5MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle m...
CVE-2025-71267MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero-size...
CVE-2025-71266MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to avoid...
CVE-2025-71265MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs_rang...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now