2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14149MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2025-14040MEDIUM6.4The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-56605MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event M...
CVE-2025-64999MEDIUM5.4Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker...
CVE-2025-3525MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18...
CVE-2025-14103MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 1...
CVE-2025-67601MEDIUM4.8A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -ski...
CVE-2025-14742MEDIUM4.3The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ...
CVE-2025-11563MEDIUM4.6URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current ...
CVE-2025-5781MEDIUM5.2Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitac...
CVE-2025-69231MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2025-68277MEDIUM5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2025-67491MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0....
CVE-2025-46320MEDIUM6.1A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access an...
CVE-2025-1787MEDIUM4.2Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin pr...
CVE-2025-62512MEDIUM5.3Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the ...
CVE-2025-47904MEDIUM4.1Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software ...
CVE-2025-10010MEDIUM6.8The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before us...
CVE-2025-27555MEDIUM6.5Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensiti...
CVE-2025-11848MEDIUM4.9A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version throu...
CVE-2025-11847MEDIUM4.9A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions thro...
CVE-2025-11846MEDIUM4.9A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions...
CVE-2025-11845MEDIUM4.9A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware ve...
CVE-2025-69253MEDIUM5.3free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of th...
CVE-2025-69251MEDIUM5.3free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now