2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62698MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62693MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-11979MEDIUM6.5An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation...
CVE-2025-6515MEDIUM6.8The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographical...
CVE-2025-60856MEDIUM6.8Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attack...
CVE-2025-48025MEDIUM4.3In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000,...
CVE-2025-40005MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle ...
CVE-2025-8884MEDIUM5.5Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Pri...
CVE-2025-61456MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoin...
CVE-2025-11680MEDIUM5.9Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during ...
CVE-2025-11679MEDIUM5.9Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled du...
CVE-2025-11677MEDIUM6.3Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker...
CVE-2025-61454MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoi...
CVE-2025-8349MEDIUM5.3Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute Java...
CVE-2025-57839MEDIUM4Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect ser...
CVE-2025-57838MEDIUM4Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may af...
CVE-2025-11947MEDIUM4.5A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the c...
CVE-2025-11946MEDIUM5.4A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process...
CVE-2025-62672MEDIUM5.3rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecifie...
CVE-2025-11926MEDIUM4.4The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2025-11256MEDIUM5.3The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2025-10750MEDIUM5.3The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, ...
CVE-2025-9562MEDIUM6.4The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs...
CVE-2025-11741MEDIUM5.3The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up t...
CVE-2025-11703MEDIUM5.3The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now