2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65887MEDIUM6.5A division-by-zero vulnerability in the flow.floor_divide() component of OneFlow v0.9.0 allows attackers to cause a Deni...
CVE-2025-13919MEDIUM4.4Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hija...
CVE-2025-13918MEDIUM6.7Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevatio...
CVE-2025-70336MEDIUM4.8A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote atta...
CVE-2025-14795MEDIUM4.3The Stop Spammers Classic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-14865MEDIUM6.4The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-59900MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59899MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59898MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59897MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-59896MEDIUM5.4Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site ...
CVE-2025-15511MEDIUM5.3The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2025-14616MEDIUM4.3The Recooty – Job Widget (Old Dashboard) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-14283MEDIUM6.4The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin ...
CVE-2025-14063MEDIUM6.1The SEO Links Interlinking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_error' p...
CVE-2025-41351MEDIUM6Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail...
CVE-2025-9082MEDIUM6.4The WPBITS Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widget pa...
CVE-2025-14039MEDIUM6.4The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_simple_folio_item_client_na...
CVE-2025-12709MEDIUM6.4The Interactions – Create Interactive Experiences in the Block Editor plugin for WordPress is vulnerable to Stored Cross...
CVE-2025-8072MEDIUM6.4The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder_img...
CVE-2025-13471MEDIUM5.3The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowin...
CVE-2025-54373MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2025-12810MEDIUM6.5Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password Rotation modules).This issue a...
CVE-2025-65264MEDIUM5.5The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface...
CVE-2025-69418MEDIUM4Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now