2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9232MEDIUM5.9Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_p...
CVE-2025-9231MEDIUM6.5Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 ...
CVE-2025-52050MEDIUM6.5In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_pr...
CVE-2025-52049MEDIUM6.5In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py ...
CVE-2025-52047MEDIUM6.5In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Inj...
CVE-2025-52043MEDIUM6.5In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_ac...
CVE-2025-10859MEDIUM4Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing info...
CVE-2025-10217MEDIUM6A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log dat...
CVE-2025-9948MEDIUM4.3The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2025-9946MEDIUM6.1The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2025-9852MEDIUM6.4The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-...
CVE-2025-8777MEDIUM6.4The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all ver...
CVE-2025-8624MEDIUM6.4The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in...
CVE-2025-8623MEDIUM6.4The WeedMaps Menu for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's weedm...
CVE-2025-8608MEDIUM6.4The Mihdan: Elementor Yandex Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blo...
CVE-2025-8566MEDIUM6.4The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in the ...
CVE-2025-8560MEDIUM6.4The FancyTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all version...
CVE-2025-8559MEDIUM6.5The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1...
CVE-2025-8214MEDIUM6.4The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typing L...
CVE-2025-8119MEDIUM4.3PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft spec...
CVE-2025-8118MEDIUM6.5PAD CMS implements weak client-side brute-force protection by utilizing two cookies:  login_count and login_timeout. Inf...
CVE-2025-8116MEDIUM6.1PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special U...
CVE-2025-6941MEDIUM6.4The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-6815MEDIUM5.5The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-59956MEDIUM6.5AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now