2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13146MEDIUM6.5The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a...
CVE-2025-68640MEDIUM5.3The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T...
CVE-2025-71398MEDIUM5.8SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-n...
CVE-2025-71393MEDIUM6SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e...
CVE-2025-71390MEDIUM5.8SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames agains...
CVE-2025-45870MEDIUM6.5LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet c...
CVE-2025-32781MEDIUM6.5Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior...
CVE-2025-62826MEDIUM4.3An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera...
CVE-2025-62675MEDIUM4.3An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera...
CVE-2025-43892MEDIUM4.3A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v...
CVE-2025-15665MEDIUM5.4The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Sl...
CVE-2025-5017MEDIUM4.9The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’...
CVE-2025-13968MEDIUM6.4The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod...
CVE-2025-30008MEDIUM5.4HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users...
CVE-2025-11977MEDIUM6.6The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin fo...
CVE-2025-12506MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and ...
CVE-2025-14785MEDIUM6.4The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor...
CVE-2025-12799MEDIUM6.5A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined config...
CVE-2025-8591MEDIUM6.1The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back ...
CVE-2025-71385MEDIUM6.1Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoi...
CVE-2025-69132MEDIUM6.5Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
CVE-2025-66076MEDIUM5.3Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
CVE-2025-15666MEDIUM5.3A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerabili...
CVE-2025-71381MEDIUM6.9Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the midd...
CVE-2025-36359MEDIUM6.5IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now