2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-0688MEDIUM6.1The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape ...
CVE-2025-0687MEDIUM6.1The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape ...
CVE-2025-0329MEDIUM4.8The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which cou...
CVE-2025-44110MEDIUM5.4FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php.
CVE-2025-43853MEDIUM5.5The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebA...
CVE-2025-1647MEDIUM5.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap a...
CVE-2025-48051MEDIUM6.1powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern i...
CVE-2025-3440MEDIUM5.5IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to ...
CVE-2025-2527MEDIUM4.3Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing gr...
CVE-2025-4701MEDIUM5.3A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue...
CVE-2025-46053MEDIUM5.1A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive...
CVE-2025-44185MEDIUM5.4SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_...
CVE-2025-4516MEDIUM5.9There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using t...
CVE-2025-44183MEDIUM6.1Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via t...
CVE-2025-44182MEDIUM6.1Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modeln...
CVE-2025-44181MEDIUM6.1Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via...
CVE-2025-44180MEDIUM6.1Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={bra...
CVE-2025-3446MEDIUM4.3Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct pe...
CVE-2025-31947MEDIUM5.3Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users f...
CVE-2025-32738MEDIUM6.9Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware...
CVE-2025-4737MEDIUM6.2Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of...
CVE-2025-27524MEDIUM5.3Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affect...
CVE-2025-48027MEDIUM5.4The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolutio...
CVE-2025-3742MEDIUM6.8The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes befo...
CVE-2025-48024MEDIUM5In BlueWave Checkmate before 2.1, an authenticated regular user can access sensitive application secrets via the /api/v1...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now