2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-23773MEDIUM6.5Missing Authorization vulnerability in mingocommerce Delete All Posts allows Exploiting Incorrectly Configured Access Co...
CVE-2025-22771MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studio Hyperset Th...
CVE-2025-22340MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Data Dash...
CVE-2025-29015MEDIUM6.1Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pa...
CVE-2025-3760MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 th...
CVE-2025-3487MEDIUM5.4The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2025-3479MEDIUM5.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Order Repl...
CVE-2025-3453MEDIUM5.3The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect...
CVE-2025-26478MEDIUM6.5Dell ECS version 3.8.1.4 and prior contain an Improper Certificate Validation vulnerability. An unauthenticated attacker...
CVE-2025-29931MEDIUM6.3A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not...
CVE-2025-2197MEDIUM4.3Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service av...
CVE-2025-3615MEDIUM6.4The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in ...
CVE-2025-3295MEDIUM4.9The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. T...
CVE-2025-43717MEDIUM5.4In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and ...
CVE-2025-31339MEDIUM5.3An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro ...
CVE-2025-31338MEDIUM6.9A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 thr...
CVE-2025-43704MEDIUM4.7Arctera/Veritas Data Insight before 7.1.2 can send cleartext credentials when configured to use HTTP Basic Authenticatio...
CVE-2025-24911MEDIUM4.9Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable...
CVE-2025-24910MEDIUM4.9Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable...
CVE-2025-24909MEDIUM4.4Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed...
CVE-2025-24908MEDIUM6.8Overview   The product uses external input to construct a pathname that should be within a restricted directory, ...
CVE-2025-24907MEDIUM6.8Overview   The product uses external input to construct a pathname that should be within a restricted directory, ...
CVE-2025-1704MEDIUM6.5ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users...
CVE-2025-0758MEDIUM6.1Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be...
CVE-2025-0757MEDIUM4.4Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now