2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15324MEDIUM6.6Tanium addressed a documentation issue in Engage.
CVE-2025-58190MEDIUM5.3The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can ...
CVE-2025-47911MEDIUM5.3The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which ...
CVE-2025-15551MEDIUM5.6The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is get...
CVE-2025-70792MEDIUM6.1Cross Site Scripting vulnerability in the "/admin/category/create" endpoint of Microweber 2.0.19. An attacker can manipu...
CVE-2025-70791MEDIUM6.1Cross Site Scripting vulnerability in the "/admin/order/abandoned" endpoint of Microweber 2.0.19. An attacker can manipu...
CVE-2025-69619MEDIUM5.5A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the i...
CVE-2025-68643MEDIUM5.4Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account pre...
CVE-2025-14150MEDIUM6.5IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM...
CVE-2025-13491MEDIUM5.1IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th...
CVE-2025-14079MEDIUM5.3The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a...
CVE-2025-13416MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspensi...
CVE-2025-10258MEDIUM6.3Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may r...
CVE-2025-68699MEDIUM6.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing /...
CVE-2025-70545MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X r...
CVE-2025-70997MEDIUM6.5A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password...
CVE-2025-69618MEDIUM6.5An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers ...
CVE-2025-14740MEDIUM6.7Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling...
CVE-2025-41085MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not p...
CVE-2025-15508MEDIUM5.3The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
CVE-2025-15507MEDIUM5.3The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-15487MEDIUM4.9The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via t...
CVE-2025-15482MEDIUM5.3The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in...
CVE-2025-15260MEDIUM6.5The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization i...
CVE-2025-14461MEDIUM5.3The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now