2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7845MEDIUM6.4The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advan...
CVE-2025-4523MEDIUM6.5The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized acc...
CVE-2025-8433MEDIUM5.4A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects...
CVE-2025-53399MEDIUM6.9In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic of the media-relay core ...
CVE-2025-48073MEDIUM6.2OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-23289MEDIUM5.5NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause ...
CVE-2025-45769MEDIUM6.5php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key leng...
CVE-2025-37112MEDIUM6A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Functi...
CVE-2025-37111MEDIUM6A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Fu...
CVE-2025-37110MEDIUM6A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Tel...
CVE-2025-54834MEDIUM6.9OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/...
CVE-2025-54832MEDIUM5.3OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of ...
CVE-2025-50866MEDIUM6.1CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of t...
CVE-2025-50867MEDIUM6.5A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where th...
CVE-2025-50848MEDIUM6.1A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3...
CVE-2025-50847MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparis...
CVE-2025-46809MEDIUM6.9A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. Thi...
CVE-2025-51569MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. Th...
CVE-2025-50270MEDIUM6.1A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remot...
CVE-2025-29557MEDIUM5.4ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where user...
CVE-2025-7738MEDIUM4.4A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub...
CVE-2025-54589MEDIUM6.1Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, use...
CVE-2025-8401MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2025-8151MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, ...
CVE-2025-8068MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now