2025 CVE Vulnerabilities

45,212 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54764MEDIUM6.2Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i...
CVE-2025-12001MEDIUM6.1Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B...
CVE-2025-11536MEDIUM5The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver...
CVE-2025-62658HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foun...
CVE-2025-62657MEDIUM5.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62656MEDIUM5.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-61303CRITICAL9.8Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability...
CVE-2025-61301HIGH7.5Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows at...
CVE-2025-60783MEDIUM6.5There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerabilit...
CVE-2025-60781MEDIUM6.1PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_nam...
CVE-2025-8053CRITICAL9.1Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac...
CVE-2025-8052HIGH8.8SQL Injection vulnerability in opentext Flipper allows SQL Injection.  The vulnerability could allow a low privilege us...
CVE-2025-8051MEDIUM6.5Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal.  The vulnerability could allow a user ...
CVE-2025-8049HIGH8.8Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac...
CVE-2025-8048MEDIUM6.5External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could a...
CVE-2025-62697HIGH8.8Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in The ...
CVE-2025-62528MEDIUM5.4Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ...
CVE-2025-62527HIGH7.1Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ...
CVE-2025-62522MEDIUM6Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5...
CVE-2025-61488HIGH7.6An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary cod...
CVE-2025-5517MEDIUM6.8Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC ...
CVE-2025-62700MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62698MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62693MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62510HIGH8.1FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now