2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8192MEDIUM6.9There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied ...
CVE-2025-24854MEDIUM6.1A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could al...
CVE-2025-7205MEDIUM5.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2025-41396MEDIUM6.5A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwri...
CVE-2025-41391MEDIUM5.4Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a maliciou...
CVE-2025-36563MEDIUM6.1Reflected cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product administrator accesse...
CVE-2025-8370MEDIUM6.1A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9. Affected is an unknown funct...
CVE-2025-8369MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9. This issue affects some...
CVE-2025-8368MEDIUM6.1A vulnerability classified as problematic was found in Portabilis i-Educar 2.9. This vulnerability affects unknown code ...
CVE-2025-8367MEDIUM6.1A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9. This affects an unknown part of the...
CVE-2025-8366MEDIUM6.1A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some u...
CVE-2025-5720MEDIUM6.4The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ ...
CVE-2025-8365MEDIUM6.1A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerabili...
CVE-2025-8347MEDIUM6.5A vulnerability, which was classified as critical, was found in Kehua Charging Pile Cloud Platform 1.0. This affects an ...
CVE-2025-8346MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue...
CVE-2025-8340MEDIUM6.1A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic....
CVE-2025-36040MEDIUM6.5IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client...
CVE-2025-36039MEDIUM6.5IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client...
CVE-2025-8337MEDIUM5.4A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This...
CVE-2025-8335MEDIUM4.3A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an ...
CVE-2025-54586MEDIUM6.5GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, att...
CVE-2025-54585MEDIUM6.5GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attac...
CVE-2025-54584MEDIUM5.7GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19...
CVE-2025-54583MEDIUM6.5GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 ...
CVE-2025-54575MEDIUM5.3ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file con...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now