2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61183MEDIUM6.1Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the stor...
CVE-2025-60833MEDIUM6.5An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to e...
CVE-2025-60830MEDIUM6.5redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.
CVE-2025-60828MEDIUM6.5WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine in...
CVE-2025-60314MEDIUM5.4Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input...
CVE-2025-43830MEDIUM6.1Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023...
CVE-2025-43829MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through ...
CVE-2025-60299MEDIUM5.4Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addComme...
CVE-2025-60298MEDIUM5.4Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updat...
CVE-2025-43821MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through...
CVE-2025-10649MEDIUM6.5The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and inc...
CVE-2025-11445MEDIUM6.3A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webv...
CVE-2025-11443MEDIUM5.9A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/passwor...
CVE-2025-11442MEDIUM4.3A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3. The impacted element is an unknown function of the c...
CVE-2025-48464MEDIUM4.7Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync a...
CVE-2025-11440MEDIUM4.3A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Execut...
CVE-2025-11439MEDIUM4.3A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/i...
CVE-2025-11438MEDIUM6.3A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /cust...
CVE-2025-11437MEDIUM4.8A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the c...
CVE-2025-11435MEDIUM6.1A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown ...
CVE-2025-11171MEDIUM5.3The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all...
CVE-2025-11433MEDIUM6.1A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of t...
CVE-2025-11425MEDIUM4.8A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Affected is an unknown function ...
CVE-2025-11421MEDIUM5.4A flaw has been found in code-projects Voting System 1.0. The affected element is an unknown function of the file /admin...
CVE-2025-61999MEDIUM4.8OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload JavaScript or other content embedded in an SV...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now