2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-70368MEDIUM5.4Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An att...
CVE-2025-57785MEDIUM6.5A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticate...
CVE-2025-57783MEDIUM5.3Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allow...
CVE-2025-50537MEDIUM5.5Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/sha...
CVE-2025-59109MEDIUM5.1The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sendin...
CVE-2025-59102MEDIUM6.9The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev...
CVE-2025-59100MEDIUM5.9The web interface offers a functionality to export the internal SQLite database. After executing the database export, an...
CVE-2025-59096MEDIUM4.6The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is...
CVE-2025-59095MEDIUM6.8The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is t...
CVE-2025-41083MEDIUM5.1Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipu...
CVE-2025-41082MEDIUM6.9Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of m...
CVE-2025-14973MEDIUM6.8The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a...
CVE-2025-71163MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind an...
CVE-2025-6461MEDIUM4.3The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers...
CVE-2025-13920MEDIUM5.3The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2025-15516MEDIUM4.3The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-14907MEDIUM4.3The Moderate Selected Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2025-14630MEDIUM4.3The AdminQuickbar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-13205MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ...
CVE-2025-13194MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ...
CVE-2025-13139MEDIUM4.3The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2025-14985MEDIUM6.4The Alpha Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alpha_block_css’ parameter i...
CVE-2025-14941MEDIUM6.4The GZSEO plugin for WordPress is vulnerable to authorization bypass leading to Stored Cross-Site Scripting in all versi...
CVE-2025-14906MEDIUM4.3The WP Youtube Video Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2025-14903MEDIUM4.3The Simple Crypto Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now