2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-39517MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Basic Interactive World Map basic-interactive-world-ma...
CVE-2025-39516MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alan Petersen Auth...
CVE-2025-39515MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tnomi Attendance M...
CVE-2025-39514MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asgaros Asgaros Fo...
CVE-2025-39513MEDIUM5.3Missing Authorization vulnerability in ActiveDEMAND Online Agency Marketing Automation ActiveDEMAND activedemand allows ...
CVE-2025-39512MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Yuya Hoshino Bulk Term Editor bulk-term-editor allows Cross Site Requ...
CVE-2025-1983MEDIUM5.1A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary ...
CVE-2025-3688MEDIUM4.8A vulnerability, which was classified as problematic, was found in mirweiye Seven Bears Library CMS 2023. This affects a...
CVE-2025-3687MEDIUM5.3A vulnerability, which was classified as problematic, has been found in misstt123 oasys 1.0. Affected by this issue is s...
CVE-2025-3686MEDIUM5.3A vulnerability classified as problematic was found in misstt123 oasys 1.0. Affected by this vulnerability is the functi...
CVE-2025-22021MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: socket: Lookup orig tuple for IPv6 SNAT ...
CVE-2025-22019MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bcachefs: bch2_ioctl_subvolume_destroy() fixes bch...
CVE-2025-31363MEDIUM6.5Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to...
CVE-2025-27936MEDIUM5.9Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enable...
CVE-2025-3677MEDIUM5.3A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the functio...
CVE-2025-3104MEDIUM5.3The WP STAGING Pro WordPress Backup Plugin for WordPress is vulnerable to Information Exposure in all versions up to and...
CVE-2025-3077MEDIUM5.4The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custo...
CVE-2025-27571MEDIUM4.3Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to check the "Allow Users to View Archived...
CVE-2025-24839MEDIUM4.3Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering ...
CVE-2025-0101MEDIUM6.5A low privileged user can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time li...
CVE-2025-3675MEDIUM5.3A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issu...
CVE-2025-3674MEDIUM6.9A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this v...
CVE-2025-3247MEDIUM5.3The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via th...
CVE-2025-3668MEDIUM6.9A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability...
CVE-2025-3667MEDIUM6.9A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now