2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67723MEDIUM5.4Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a cont...
CVE-2025-66488MEDIUM6.1Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12....
CVE-2025-57796MEDIUM6.8Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sen...
CVE-2025-46316MEDIUM4.3An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPad...
CVE-2025-46306MEDIUM5.5The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Ta...
CVE-2025-33237MEDIUM5.5NVIDIA HD Audio Driver for Windows contains a vulnerability where an attacker could exploit a NULL pointer dereference i...
CVE-2025-65887MEDIUM6.5A division-by-zero vulnerability in the flow.floor_divide() component of OneFlow v0.9.0 allows attackers to cause a Deni...
CVE-2025-13919MEDIUM4.4Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hija...
CVE-2025-13918MEDIUM6.7Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevatio...
CVE-2025-70336MEDIUM4.8A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote atta...
CVE-2025-14795MEDIUM4.3The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14865MEDIUM6.4The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-59900MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59899MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59898MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59897MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59896MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-15511MEDIUM5.3The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2025-14616MEDIUM4.3The Recooty – Job Widget (Old Dashboard) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-14283MEDIUM6.4The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin ...
CVE-2025-14063MEDIUM6.1The SEO Links Interlinking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_error' p...
CVE-2025-41351MEDIUM6Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail...
CVE-2025-9082MEDIUM6.4The WPBITS Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget pa...
CVE-2025-14039MEDIUM6.4The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_simple_folio_item_client_na...
CVE-2025-12709MEDIUM6.4The Interactions – Create Interactive Experiences in the Block Editor plugin for WordPress is vulnerable to Stored Cross...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now