2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7834MEDIUM4.3A vulnerability, which was classified as problematic, was found in PHPGurukul Complaint Management System 2.0. Affected ...
CVE-2025-7819MEDIUM5.4A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as problematic....
CVE-2025-7818MEDIUM5.4A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as problematic. Affected...
CVE-2025-7817MEDIUM5.4A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as problematic. Aff...
CVE-2025-38351MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: x86/hyper-v: Skip non-canonical addresses duri...
CVE-2025-7816MEDIUM5.4A vulnerability, which was classified as problematic, was found in PHPGurukul Apartment Visitors Management System 1.0. ...
CVE-2025-7815MEDIUM5.4A vulnerability, which was classified as problematic, has been found in PHPGurukul Apartment Visitors Management System ...
CVE-2025-6997MEDIUM5.4The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2025-6721MEDIUM5.3The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on ...
CVE-2025-6720MEDIUM5.3The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on th...
CVE-2025-7669MEDIUM6.1The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2025-7661MEDIUM6.4The Partnerský systém Martinus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'marti...
CVE-2025-7658MEDIUM6.4The Temporarily Hidden Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'temph...
CVE-2025-7655MEDIUM6.4The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' s...
CVE-2025-7653MEDIUM6.4The EPay.bg Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'epay' shortcode...
CVE-2025-52924MEDIUM4In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untruste...
CVE-2025-7396MEDIUM4.6In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding conf...
CVE-2025-50583MEDIUM4.8StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module...
CVE-2025-50582MEDIUM4.8StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.
CVE-2025-50581MEDIUM4.8MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do...
CVE-2025-7803MEDIUM5.1A vulnerability was found in descreekert wx-discuz up to 12bd4745c63ec203cb32119bf77ead4a923bf277. It has been classifie...
CVE-2025-54310MEDIUM5.3qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidge...
CVE-2025-50584MEDIUM4.8StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module...
CVE-2025-7802MEDIUM5.4A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as problematic. Affected by this ...
CVE-2025-7800MEDIUM5.1A vulnerability classified as problematic was found in cgpandey hotelmis up to c572198e6c4780fccc63b1d3e8f3f72f825fc94e....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now