2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10456MEDIUM6.5A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specif...
CVE-2025-10146MEDIUM6.1The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter i...
CVE-2025-8487MEDIUM5.4The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capabi...
CVE-2025-59715MEDIUM5.4SMSEagle before 6.11 allows reflected XSS via a username or contact phone number.
CVE-2025-59714MEDIUM4.9In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.
CVE-2025-59712MEDIUM5.4Snipe-IT before 8.1.18 allows XSS.
CVE-2025-30755MEDIUM6.1OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens t...
CVE-2025-47906MEDIUM6.5If the PATH environment variable contains paths which are executables (rather than just directories), passing certain st...
CVE-2025-26503MEDIUM6.7A crafted system call argument can cause memory corruption.
CVE-2025-36146MEDIUM4.3IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version informat...
CVE-2025-36139MEDIUM4.8IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged us...
CVE-2025-10676MEDIUM4.3A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /b...
CVE-2025-10675MEDIUM4.3A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of t...
CVE-2025-10674MEDIUM4.3A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController o...
CVE-2025-59417MEDIUM6.1Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site sc...
CVE-2025-59040MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representa...
CVE-2025-57452MEDIUM6.1In realme BackupRestore app v15.1.12_2810c08_250314, improper URI scheme handling in com.coloros.pc.PcToolMainActivity a...
CVE-2025-55911MEDIUM6.5An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an...
CVE-2025-4444MEDIUM6.3A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Oni...
CVE-2025-10669MEDIUM6.3A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component...
CVE-2025-40678MEDIUM5.3Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability ...
CVE-2025-9992MEDIUM6.4The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-0547MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof...
CVE-2025-10493MEDIUM5.3The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via t...
CVE-2025-10642MEDIUM5.1A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now