2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-43977MEDIUM5.5The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) t...
CVE-2025-43976MEDIUM5.5The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no p...
CVE-2025-7926MEDIUM5.4A vulnerability, which was classified as problematic, was found in PHPGurukul Online Banquet Booking System 1.0. This af...
CVE-2025-6235MEDIUM6.1In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the ...
CVE-2025-7925MEDIUM6.1A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Banquet Booking System 1.0. Af...
CVE-2025-41100MEDIUM5.9Incorrect authentication vulnerability in ParkingDoor. Through this vulnerability it is possible to operate the device w...
CVE-2025-2301MEDIUM4.4Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploit...
CVE-2025-7924MEDIUM5.4A vulnerability classified as problematic was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vu...
CVE-2025-5681MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted ...
CVE-2025-41458MEDIUM5.5Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive...
CVE-2025-41681MEDIUM4.8A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special el...
CVE-2025-41677MEDIUM4.9A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to...
CVE-2025-41676MEDIUM4.9A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to...
CVE-2025-7369MEDIUM6.1The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v...
CVE-2025-7354MEDIUM6.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-4685MEDIUM6.4The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2025-4570MEDIUM6.9An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token t...
CVE-2025-7920MEDIUM6.1WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unau...
CVE-2025-0664MEDIUM6.7A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent...
CVE-2025-53771MEDIUM6.5Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ...
CVE-2025-7907MEDIUM4.3A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unkn...
CVE-2025-54319MEDIUM6.3An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized acces...
CVE-2025-7906MEDIUM5.4A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function...
CVE-2025-54316MEDIUM4.9An issue was discovered in Logpoint before 7.6.0. When creating reports, attackers can create custom Jinja templates tha...
CVE-2025-7903MEDIUM5.4A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now