2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-60852MEDIUM6.5A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built wi...
CVE-2025-53702MEDIUM6.5Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same l...
CVE-2025-53701MEDIUM6.1Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET re...
CVE-2025-1680NONE0An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switch...
CVE-2025-1679MEDIUM4.8Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attac...
CVE-2025-11429MEDIUM5.4A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on ...
CVE-2025-8427MEDIUM5.4The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a...
CVE-2025-11128MEDIUM5The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2025-11023CRITICAL9.8Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in ...
CVE-2025-10705MEDIUM5.3The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver...
CVE-2025-62401MEDIUM4.3An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them m...
CVE-2025-62400MEDIUM6.5Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden g...
CVE-2025-62399HIGH7.5Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, makin...
CVE-2025-62398MEDIUM5.4A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certa...
CVE-2025-62397MEDIUM5.3The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially ...
CVE-2025-62396MEDIUM5.3An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings ...
CVE-2025-62395MEDIUM4.3A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information fr...
CVE-2025-62394MEDIUM4.3Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive u...
CVE-2025-62393MEDIUM4.3A flaw was found in the course overview output function where user access permissions were not fully enforced. This coul...
CVE-2025-10355MEDIUM5.1Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious UR...
CVE-2025-41073MEDIUM6.5Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated atta...
CVE-2025-40643MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du...
CVE-2025-9981MEDIUM4.8QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with adm...
CVE-2025-9980MEDIUM4.8QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin p...
CVE-2025-12105HIGH7.5A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-base...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now