2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2070MEDIUM5.1An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the syst...
CVE-2025-2069MEDIUM5.1A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted ur...
CVE-2025-2068MEDIUM5.1An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url...
CVE-2025-46618MEDIUM6.1In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
CVE-2025-46432MEDIUM6.5In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs
CVE-2025-3647MEDIUM4.3A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they a...
CVE-2025-3645MEDIUM4.3A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users'...
CVE-2025-3644MEDIUM4.3A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not ...
CVE-2025-3643MEDIUM5.4A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cros...
CVE-2025-3640MEDIUM4.3A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access so...
CVE-2025-3636MEDIUM4.3A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficien...
CVE-2025-3628MEDIUM4.3A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student...
CVE-2025-3627MEDIUM4.3A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other stu...
CVE-2025-32045MEDIUM5.3A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without...
CVE-2025-28076MEDIUM6.5Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.4 and CO2Scope <= 1.3.4 allows remote authenticated at...
CVE-2025-3634MEDIUM4.3A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completin...
CVE-2025-28354MEDIUM6.5An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a ...
CVE-2025-3912MEDIUM5.3The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized acc...
CVE-2025-2986MEDIUM5.4IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged...
CVE-2025-3870MEDIUM6.1The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi...
CVE-2025-46535MEDIUM5.4Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly C...
CVE-2025-46482MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Qui...
CVE-2025-3868MEDIUM6.1The Custom Admin-Bar Favorites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'menuObject'...
CVE-2025-3867MEDIUM6.1The Ajax Comment Form CST plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2025-3866MEDIUM6.1The Add Google +1 (Plus one) social share Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now