2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-51971MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Adv...
CVE-2025-51969MEDIUM6.5A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This...
CVE-2025-51968MEDIUM6.5A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The a...
CVE-2025-51967MEDIUM6.1A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Manag...
CVE-2025-58127MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin Dell Powerscale allows attackers in MitM position to intercep...
CVE-2025-58126MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin VMware vSAN allows attackers in MitM position to intercept tr...
CVE-2025-58125MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to interce...
CVE-2025-58124MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept t...
CVE-2025-58123MEDIUM4.8Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept...
CVE-2025-54734MEDIUM5.8Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Contro...
CVE-2025-54733MEDIUM6.5Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting ...
CVE-2025-53337MEDIUM5.4Missing Authorization vulnerability in Ashan Perera LifePress lifepress allows Exploiting Incorrectly Configured Access ...
CVE-2025-53250MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in Chartbeat Chartbeat chartbeat allows Server Side Request Forgery.Thi...
CVE-2025-49405MEDIUM4.3Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-48365MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imaprogrammer Cust...
CVE-2025-48364MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in vEnCa-X rajce rajce allows Server Side Request Forgery.This issue af...
CVE-2025-48363MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Metin Saraç Popup for CF7 with Sweet Alert cf7-sweet-alert-popup allo...
CVE-2025-48362MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Saeed Sattar Beglou Hesabfa Accounting hesabfa-accounting allows Cros...
CVE-2025-48361MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Saeed Sattar Beglou Hesabfa Accounting hesabfa-accoun...
CVE-2025-48360MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Razvan Stanga Varn...
CVE-2025-48358MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in everythingwp Risk ...
CVE-2025-48357MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Theme Century Century ToolKit century-toolkit allows Cross Site Reque...
CVE-2025-48356MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Isra Kanpress kanp...
CVE-2025-48354MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Smart Widgets B...
CVE-2025-48352MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sitesearch-yandex ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now