2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8072MEDIUM6.4The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder_img...
CVE-2025-13471MEDIUM5.3The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowin...
CVE-2025-54373MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2025-12810MEDIUM6.5Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue a...
CVE-2025-65264MEDIUM5.5The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface...
CVE-2025-69418MEDIUM4Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs...
CVE-2025-68160MEDIUM4.7Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO perf...
CVE-2025-66199MEDIUM5.9Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp...
CVE-2025-28164MEDIUM5.5Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_creat...
CVE-2025-28162MEDIUM5.5Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngim...
CVE-2025-15469MEDIUM5.5Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing al...
CVE-2025-15468MEDIUM5.9Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un...
CVE-2025-11187MEDIUM6.1Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow...
CVE-2025-41728MEDIUM5.3A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged proces...
CVE-2025-12387MEDIUM6.9A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service...
CVE-2025-12386MEDIUM6.9Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticat...
CVE-2025-14971MEDIUM5.3The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-9820MEDIUM4A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok...
CVE-2025-9522MEDIUM5.3Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t...
CVE-2025-9521MEDIUM6.5Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa...
CVE-2025-9520MEDIUM6.8An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate r...
CVE-2025-14969MEDIUM4.3A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client...
CVE-2025-14525MEDIUM6.4A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by ca...
CVE-2025-11687MEDIUM6.1A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page —...
CVE-2025-11065MEDIUM5.3A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now