2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-5405MEDIUM5.4A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b5...
CVE-2025-33004MEDIUM6.5IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper ...
CVE-2025-2896MEDIUM5.4IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticat...
CVE-2025-25044MEDIUM5.4IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticat...
CVE-2025-1499MEDIUM6.5IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext paramete...
CVE-2025-5383MEDIUM4.8A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknow...
CVE-2025-5380MEDIUM6.3A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ad...
CVE-2025-5379MEDIUM5.3A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects...
CVE-2025-5378MEDIUM6.1A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown ...
CVE-2025-5377MEDIUM6.1A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issu...
CVE-2025-4691MEDIUM5.3The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to I...
CVE-2025-5290MEDIUM6.4The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-3813MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_ele...
CVE-2025-5292MEDIUM6.4The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Buil...
CVE-2025-5285MEDIUM6.4The Product Subtitle for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmlTag’...
CVE-2025-4595MEDIUM6.4The FastSpring plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fastspring/block-fast...
CVE-2025-4590MEDIUM6.4The Daisycon prijsvergelijkers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'daisy...
CVE-2025-5016MEDIUM4.7The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highl...
CVE-2025-48948MEDIUM6.5Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions p...
CVE-2025-1479MEDIUM5.3An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a ...
CVE-2025-48944MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, th...
CVE-2025-48943MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a...
CVE-2025-48942MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, h...
CVE-2025-48885MEDIUM5.7application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with vie...
CVE-2025-48883MEDIUM5.3Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Se...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now