2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-69619MEDIUM5.5A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the i...
CVE-2025-68643MEDIUM5.4Axigen Mail Server before 10.5.57 allows stored Cross-Site Scripting (XSS) in the handling of the timeFormat account pre...
CVE-2025-14150MEDIUM6.5IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM...
CVE-2025-13491MEDIUM5.1IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 th...
CVE-2025-14079MEDIUM5.3The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in a...
CVE-2025-13416MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspensi...
CVE-2025-10258MEDIUM6.3Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may r...
CVE-2025-68699MEDIUM6.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing /...
CVE-2025-70545MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X r...
CVE-2025-70997MEDIUM6.5A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password...
CVE-2025-69618MEDIUM6.5An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers ...
CVE-2025-14740MEDIUM6.7Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling...
CVE-2025-41085MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not p...
CVE-2025-15508MEDIUM5.3The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
CVE-2025-15507MEDIUM5.3The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2025-15487MEDIUM4.9The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via t...
CVE-2025-15482MEDIUM5.3The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in...
CVE-2025-15260MEDIUM6.5The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization i...
CVE-2025-14461MEDIUM5.3The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, a...
CVE-2025-69620MEDIUM5A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the in...
CVE-2025-36033MEDIUM5.4IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 th...
CVE-2025-33081MEDIUM5.5IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user...
CVE-2025-65081MEDIUM6.9An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This v...
CVE-2025-65080MEDIUM6.9A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulner...
CVE-2025-65079MEDIUM6.9A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now