2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15647MEDIUM5.5CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge in...
CVE-2025-14945MEDIUM5.4The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-15691MEDIUM5.3The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before cre...
CVE-2025-8945MEDIUM5.3The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be ...
CVE-2025-15490MEDIUM5.3The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users t...
CVE-2025-15489MEDIUM5.3The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated u...
CVE-2025-15481MEDIUM5.3The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all ...
CVE-2025-7963MEDIUM6.4The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywavefor...
CVE-2025-15664MEDIUM6.8The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's b...
CVE-2025-15663MEDIUM6.8The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's a...
CVE-2025-15613MEDIUM6.5Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attack...
CVE-2025-63607MEDIUM6.1TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter v...
CVE-2025-64649MEDIUM5.9IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te...
CVE-2025-36290MEDIUM5.9IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid...
CVE-2025-36271MEDIUM5.9IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could a...
CVE-2025-62342MEDIUM6.4HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of...
CVE-2025-70340MEDIUM6.5A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms ...
CVE-2025-10903MEDIUM6.5GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19....
CVE-2025-9878MEDIUM6.4The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cr...
CVE-2025-36939MEDIUM5.7Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread net...
CVE-2025-68833MEDIUM5.3HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker u...
CVE-2025-15671MEDIUM5.4The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and s...
CVE-2025-62306MEDIUM5HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability a...
CVE-2025-62300MEDIUM5.9HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can...
CVE-2025-62299MEDIUM6.6HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to acces...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now