2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59801MEDIUM4.3In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because th...
CVE-2025-59800MEDIUM5.5In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a h...
CVE-2025-59799MEDIUM5.5Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm....
CVE-2025-59798MEDIUM5.5Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
CVE-2025-10777MEDIUM6.3A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown function of the file /d...
CVE-2025-10774MEDIUM4.7A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown part of the file /view...
CVE-2025-10772MEDIUM6.3A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown function...
CVE-2025-10770MEDIUM6.5A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDra...
CVE-2025-10767MEDIUM4.5A vulnerability was detected in CosmodiumCS OnlyRAT up to 3.2. The affected element is the function connect/remote_uploa...
CVE-2025-10766MEDIUM4.3A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file Event...
CVE-2025-10763MEDIUM6.3A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by th...
CVE-2025-10762MEDIUM6.3A vulnerability was found in kuaifan DooTask up to 1.2.49. Affected by this vulnerability is an unknown functionality of...
CVE-2025-10760MEDIUM6.3A flaw has been found in Harness 3.3.0. This impacts the function LookupRepo of the file app/api/controller/gitspace/loo...
CVE-2025-10759MEDIUM5.5A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token...
CVE-2025-10758MEDIUM4.8A security vulnerability has been detected in htmly up to 3.1.0. The impacted element is an unknown function of the file...
CVE-2025-10755MEDIUM6.3A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component...
CVE-2025-10741MEDIUM6.3A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown funct...
CVE-2025-9887MEDIUM4.3The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-9883MEDIUM6.1The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-9882MEDIUM6.1The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-10658MEDIUM6.5The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass...
CVE-2025-9949MEDIUM4.3The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-10489MEDIUM4.3The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPres...
CVE-2025-10305MEDIUM5.3The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the d...
CVE-2025-10181MEDIUM6.4The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now