2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2890MEDIUM6.5The tagDiv Opt-In Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘subscriptionCouponId’ ...
CVE-2025-3953MEDIUM5.4The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorize...
CVE-2025-3471MEDIUM4.9The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the...
CVE-2025-46552MEDIUM6.3KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join yo...
CVE-2025-46550MEDIUM6.1YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are...
CVE-2025-46549MEDIUM6.1YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting at...
CVE-2025-46344MEDIUM4.9The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from ...
CVE-2025-3910MEDIUM5.4A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions...
CVE-2025-4078MEDIUM5.3A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects s...
CVE-2025-4095MEDIUM4.3Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers t...
CVE-2025-4076MEDIUM6.3A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_...
CVE-2025-4075MEDIUM5.3A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unk...
CVE-2025-46350MEDIUM4.8YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting at...
CVE-2025-46349MEDIUM6.1YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file uplo...
CVE-2025-3911MEDIUM5.2Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to ...
CVE-2025-0716MEDIUM4.8Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allo...
CVE-2025-46346MEDIUM5.4YesWiki is a wiki system written in PHP. Prior to version 4.5.4, a stored cross-site scripting (XSS) vulnerability was d...
CVE-2025-40616MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScrip...
CVE-2025-40615MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScrip...
CVE-2025-23179MEDIUM5.5CWE-798: Use of Hard-coded Credentials
CVE-2025-1551MEDIUM6.1IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This v...
CVE-2025-4067MEDIUM6.9A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unkno...
CVE-2025-4092MEDIUM6.5Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption a...
CVE-2025-4090MEDIUM5.3A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat....
CVE-2025-4089MEDIUM5.1Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into us...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now