2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-32736MEDIUM4.9Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may all...
CVE-2025-71413MEDIUM5.3Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w...
CVE-2025-71411MEDIUM5.3Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic c...
CVE-2025-71410MEDIUM5.3Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and...
CVE-2025-6508MEDIUM4.3The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b...
CVE-2025-12317MEDIUM5When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue...
CVE-2025-9266MEDIUM4.3The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2025-13909MEDIUM4.3The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT...
CVE-2025-13394MEDIUM5.4The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque...
CVE-2025-11850MEDIUM4.3When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us...
CVE-2025-15678MEDIUM6.1The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use...
CVE-2025-15631MEDIUM5.9A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al...
CVE-2025-15630MEDIUM5.9A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t...
CVE-2025-15544MEDIUM5.9A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials assoc...
CVE-2025-9291MEDIUM6.5A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif...
CVE-2025-15673MEDIUM4.9The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an...
CVE-2025-71401MEDIUM5.9better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B...
CVE-2025-15675MEDIUM4.8The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor...
CVE-2025-71404MEDIUM5.1better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ...
CVE-2025-14073MEDIUM5.3The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur...
CVE-2025-14469MEDIUM4.3The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-15669MEDIUM4.8The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren...
CVE-2025-62347MEDIUM4.3HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and...
CVE-2025-67651MEDIUM6.9A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF ...
CVE-2025-65342MEDIUM6.1code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now