2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-3782MEDIUM6.4The Cision Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all version...
CVE-2025-27248MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
CVE-2025-27241MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
CVE-2025-25218MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
CVE-2025-25052MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through buffer overflow.
CVE-2025-22886MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2025-4333MEDIUM6.3A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critic...
CVE-2025-46593MEDIUM5.5Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulner...
CVE-2025-46592MEDIUM5.5Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerabilit...
CVE-2025-46591MEDIUM5.5Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability ...
CVE-2025-46590MEDIUM6.5Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vul...
CVE-2025-46587MEDIUM5.5Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may a...
CVE-2025-3281MEDIUM5.3The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln...
CVE-2025-3020MEDIUM5.4An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several ...
CVE-2025-4329MEDIUM5.3A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the functio...
CVE-2025-4328MEDIUM5.1A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declar...
CVE-2025-4327MEDIUM5.3A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The ma...
CVE-2025-46586MEDIUM5.5Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect...
CVE-2025-46584MEDIUM5.5Vulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation ...
CVE-2025-4326MEDIUM5.4A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of th...
CVE-2025-4325MEDIUM4.8A vulnerability has been found in MRCMS 3.1.2 and classified as problematic. This vulnerability affects unknown code of ...
CVE-2025-4324MEDIUM5.4A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file...
CVE-2025-4337MEDIUM4.3The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-4323MEDIUM5.4A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unkn...
CVE-2025-4310MEDIUM6.3A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unk...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now