2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11536MEDIUM5The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver...
CVE-2025-62657MEDIUM5.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62656MEDIUM5.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-60783MEDIUM6.5There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerabilit...
CVE-2025-60781MEDIUM6.1PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_nam...
CVE-2025-8051MEDIUM6.5Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal.  The vulnerability could allow a user ...
CVE-2025-8048MEDIUM6.5External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could a...
CVE-2025-62528MEDIUM5.4Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ...
CVE-2025-62522MEDIUM6Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5...
CVE-2025-5517MEDIUM6.8Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC ...
CVE-2025-62700MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62698MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62693MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-11979MEDIUM6.5An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation...
CVE-2025-6515MEDIUM6.8The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographical...
CVE-2025-60856MEDIUM6.8Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attack...
CVE-2025-48025MEDIUM4.3In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000,...
CVE-2025-40005MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle ...
CVE-2025-8884MEDIUM5.5Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Pri...
CVE-2025-61456MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoin...
CVE-2025-11680MEDIUM5.9Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during ...
CVE-2025-11679MEDIUM5.9Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled du...
CVE-2025-11677MEDIUM6.3Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker...
CVE-2025-61454MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoi...
CVE-2025-8349MEDIUM5.3Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute Java...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now