2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67547MEDIUM6.5Missing Authorization vulnerability in uixthemes Konte konte allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2025-67438MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability in Sync-in Server before 1.9.3 allows an authenticated attacker to exe...
CVE-2025-60183MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silence Silencesof...
CVE-2025-59819MEDIUM6.5This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an int...
CVE-2025-9208MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ W...
CVE-2025-8055MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery.  The vulnerabi...
CVE-2025-13672MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ W...
CVE-2025-13671MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forger...
CVE-2025-69725MEDIUM4.7An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect vi...
CVE-2025-69674MEDIUM6.4Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute ar...
CVE-2025-71244MEDIUM6.1SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a m...
CVE-2025-71242MEDIUM6.5SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does n...
CVE-2025-71241MEDIUM6.1SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error me...
CVE-2025-71240MEDIUM5.4SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not pro...
CVE-2025-15563MEDIUM5.3Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the...
CVE-2025-15562MEDIUM6.1The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper enco...
CVE-2025-41023MEDIUM6.9An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to by...
CVE-2025-40697MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to ...
CVE-2025-14983MEDIUM6.4The Advanced Custom Fields: Font Awesome Field plugin for WordPress is vulnerable to Cross-Site Scripting in all version...
CVE-2025-14864MEDIUM4.3The Virusdie - One-click website security plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve...
CVE-2025-14851MEDIUM6.4The YaMaps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `yamap` shortcode par...
CVE-2025-14445MEDIUM6.4The Image Hotspot by DevVN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hotspot_content' c...
CVE-2025-14427MEDIUM4.3The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to u...
CVE-2025-14357MEDIUM5.3The Mega Store Woocommerce theme for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2025-14342MEDIUM4.3The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now