2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-5054MEDIUM4.7Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via ...
CVE-2025-48887MEDIUM6.5vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDo...
CVE-2025-3611MEDIUM4.3Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restr...
CVE-2025-3230MEDIUM5.4Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate...
CVE-2025-2571MEDIUM4.2Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth c...
CVE-2025-4598MEDIUM4.7A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace...
CVE-2025-40909MEDIUM5.9Perl threads have a working directory race condition where file operations may target unintended paths. If a directory ...
CVE-2025-1484MEDIUM6.5A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploite...
CVE-2025-4944MEDIUM6.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2025-4597MEDIUM6.5The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modific...
CVE-2025-5235MEDIUM5.4The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ paramete...
CVE-2025-5142MEDIUM6.5The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-4635MEDIUM6.6A malicious user with administrative privileges in the web portal would be able to manipulate the Diagnostics module to ...
CVE-2025-4634MEDIUM4.1The web portal on airpointer 2.4.107-2 was vulnerable local file inclusion. A malicious user with administrative privile...
CVE-2025-4633MEDIUM6.5Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor...
CVE-2025-48912MEDIUM6.5An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injec...
CVE-2025-48334MEDIUM4.3Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro woo-slider-pro-drag-drop-slider-builder-for-woocom...
CVE-2025-5236MEDIUM5.4The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ par...
CVE-2025-4431MEDIUM4.3The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modificatio...
CVE-2025-4943MEDIUM5.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-...
CVE-2025-48880MEDIUM6.6FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account i...
CVE-2025-48875MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validatio...
CVE-2025-48489MEDIUM4.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to...
CVE-2025-48488MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allo...
CVE-2025-48487MEDIUM4.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now