2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9646MEDIUM5.4A security flaw has been discovered in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /x_organ...
CVE-2025-40709MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura...
CVE-2025-40708MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura...
CVE-2025-40707MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura...
CVE-2025-40706MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura...
CVE-2025-40705MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura...
CVE-2025-40704MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura...
CVE-2025-40703MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura...
CVE-2025-40702MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultura...
CVE-2025-9217MEDIUM6.5The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 ...
CVE-2025-7383MEDIUM5.9Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and...
CVE-2025-7071MEDIUM5.9Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.1.0 and prior to ...
CVE-2025-4644MEDIUM5.3A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A ...
CVE-2025-4643MEDIUM6.3Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker wh...
CVE-2025-8150MEDIUM6.4The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewr...
CVE-2025-54777MEDIUM5.3Uncaught exception issue exists in Multiple products in bizhub series. If a malformed file is imported as an S/MIME Emai...
CVE-2025-9441MEDIUM6.5The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all ve...
CVE-2025-9374MEDIUM4.3The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2025-8619MEDIUM6.4The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map ...
CVE-2025-8290MEDIUM6.4The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver...
CVE-2025-8147MEDIUM4.3The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on th...
CVE-2025-9619MEDIUM6.9A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of...
CVE-2025-39246MEDIUM5.3There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated u...
CVE-2025-39245MEDIUM4.7There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject e...
CVE-2025-9604MEDIUM6.3A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now