2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-63051MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in sizam REHub Framework rehub-...
CVE-2025-63026MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand R...
CVE-2025-63019MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Johan Jonk Stenström Cookies and Content Security Pol...
CVE-2025-63018MEDIUM4.3Missing Authorization vulnerability in wproyal Bard bard allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2025-62754MEDIUM5.3Missing Authorization vulnerability in Kapil Paul Payment Gateway bKash for WC woo-payment-bkash allows Exploiting Incor...
CVE-2025-62741MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request...
CVE-2025-62106MEDIUM5.4Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured...
CVE-2025-62077MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SEOSEON EUROPE S.L...
CVE-2025-5805MEDIUM6.5Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-54002MEDIUM6.5Missing Authorization vulnerability in Jthemes xSmart xsmart allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2025-50005MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp...
CVE-2025-49375MEDIUM5.4Missing Authorization vulnerability in cozythemes HomeLancer homelancer allows Exploiting Incorrectly Configured Access ...
CVE-2025-49336MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pondol Pondol BBS ...
CVE-2025-47600MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in xtemos WoodMart woodmart ...
CVE-2025-47500MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Intal Sta...
CVE-2025-31413MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in bdthemes Element Pack Elementor Addons bdthemes-element-pack-lite all...
CVE-2025-69820MEDIUM6Directory Traversal vulnerability in Beam beta9 v.0.1.521 allows a remote attacker to obtain sensitive information via t...
CVE-2025-69612MEDIUM6.5A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software....
CVE-2025-32057MEDIUM6.5The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-...
CVE-2025-32056MEDIUM4The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head...
CVE-2025-15523MEDIUM4.8MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permis...
CVE-2025-67683MEDIUM6.1Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when ope...
CVE-2025-4763MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aida Comput...
CVE-2025-13335MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 1...
CVE-2025-71176MEDIUM6.8pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now