2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8380MEDIUM5.4A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability...
CVE-2025-40980MEDIUM5.1A Stored Cross Site Scripting vulnerability has been found in UltimatePOS by UltimateFosters. This vulnerability is due ...
CVE-2025-8192MEDIUM6.9There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied ...
CVE-2025-24854MEDIUM6.1A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could al...
CVE-2025-7205MEDIUM5.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2025-41396MEDIUM6.5A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwri...
CVE-2025-41391MEDIUM5.4Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a maliciou...
CVE-2025-36563MEDIUM6.1Reflected cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product administrator accesse...
CVE-2025-8370MEDIUM6.1A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9. Affected is an unknown funct...
CVE-2025-8369MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9. This issue affects some...
CVE-2025-8368MEDIUM6.1A vulnerability classified as problematic was found in Portabilis i-Educar 2.9. This vulnerability affects unknown code ...
CVE-2025-8367MEDIUM6.1A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9. This affects an unknown part of the...
CVE-2025-8366MEDIUM6.1A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some u...
CVE-2025-5720MEDIUM6.4The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ ...
CVE-2025-8365MEDIUM6.1A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerabili...
CVE-2025-8347MEDIUM6.5A vulnerability, which was classified as critical, was found in Kehua Charging Pile Cloud Platform 1.0. This affects an ...
CVE-2025-8346MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue...
CVE-2025-8340MEDIUM6.1A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic....
CVE-2025-36040MEDIUM6.5IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client...
CVE-2025-36039MEDIUM6.5IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client...
CVE-2025-8337MEDIUM5.4A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This...
CVE-2025-8335MEDIUM4.3A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an ...
CVE-2025-54586MEDIUM6.5GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, att...
CVE-2025-54585MEDIUM6.5GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attac...
CVE-2025-54584MEDIUM5.7GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now