2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-3824MEDIUM4.1A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. ...
CVE-2025-3823MEDIUM4.1A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System ...
CVE-2025-3822MEDIUM5.4A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as probl...
CVE-2025-3821MEDIUM5.4A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as pr...
CVE-2025-43921MEDIUM5.3GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/cr...
CVE-2025-43918MEDIUM6.4SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a ...
CVE-2025-3818MEDIUM6.3A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._...
CVE-2025-3808MEDIUM6.5A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknow...
CVE-2025-3806MEDIUM4.8A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3. Affected by this iss...
CVE-2025-3805MEDIUM5.3A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc54...
CVE-2025-3804MEDIUM5.3A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function o...
CVE-2025-3801MEDIUM4.8A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an u...
CVE-2025-3661MEDIUM6.4The SB Chart block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in al...
CVE-2025-3275MEDIUM6.4The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slide...
CVE-2025-1457MEDIUM6.4The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is v...
CVE-2025-3284MEDIUM4.3The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln...
CVE-2025-36625MEDIUM4.3In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http...
CVE-2025-32377MEDIUM6.5Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models...
CVE-2025-25984MEDIUM6.8An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proxim...
CVE-2025-28355MEDIUM4.7Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execu...
CVE-2025-29513MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in ...
CVE-2025-29512MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and...
CVE-2025-32796MEDIUM6.5Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY...
CVE-2025-32795MEDIUM6.5Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY...
CVE-2025-32389MEDIUM6.5NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now