2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-34155MEDIUM6.9Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authen...
CVE-2025-50951MEDIUM6.5FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.
CVE-2025-50949MEDIUM6.5FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.
CVE-2025-12114MEDIUM5.5Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue af...
CVE-2025-56009MEDIUM5.3Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take...
CVE-2025-56008MEDIUM6.1Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near t...
CVE-2025-56007MEDIUM6.5CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding addi...
CVE-2025-12110MEDIUM5.4A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the...
CVE-2025-62256MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA...
CVE-2025-60852MEDIUM6.5A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built wi...
CVE-2025-53702MEDIUM6.5Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same l...
CVE-2025-53701MEDIUM6.1Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET re...
CVE-2025-1679MEDIUM4.8Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attac...
CVE-2025-11429MEDIUM5.4A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on ...
CVE-2025-8427MEDIUM5.4The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a...
CVE-2025-11128MEDIUM5The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2025-10705MEDIUM5.3The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver...
CVE-2025-62401MEDIUM4.3An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them m...
CVE-2025-62400MEDIUM6.5Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden g...
CVE-2025-62398MEDIUM5.4A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certa...
CVE-2025-62397MEDIUM5.3The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially ...
CVE-2025-62396MEDIUM5.3An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings ...
CVE-2025-62395MEDIUM4.3A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information fr...
CVE-2025-62394MEDIUM4.3Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive u...
CVE-2025-62393MEDIUM4.3A flaw was found in the course overview output function where user access permissions were not fully enforced. This coul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now