2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2083MEDIUM6.4The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sliderId’ p...
CVE-2025-3622MEDIUM5.5A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects t...
CVE-2025-3576MEDIUM5.9A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due...
CVE-2025-32993MEDIUM6.5Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-...
CVE-2025-2225MEDIUM5.4The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne...
CVE-2025-3573MEDIUM6.1Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() ...
CVE-2025-3613MEDIUM5.1A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unkn...
CVE-2025-3612MEDIUM5.3A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part...
CVE-2025-3470MEDIUM4.9The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s ...
CVE-2025-32997MEDIUM5.3In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.
CVE-2025-32996MEDIUM5.3In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.
CVE-2025-32987MEDIUM6Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password ...
CVE-2025-3592MEDIUM5.4A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This aff...
CVE-2025-3591MEDIUM5.4A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this ...
CVE-2025-3590MEDIUM6.3A vulnerability has been found in Adianti Framework up to 8.0 and classified as critical. Affected by this vulnerability...
CVE-2025-3588MEDIUM5.3A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. This issue ...
CVE-2025-29720MEDIUM4.8Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_fi...
CVE-2025-2572MEDIUM5.3In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated a...
CVE-2025-3571MEDIUM6.3A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as cri...
CVE-2025-3570MEDIUM6.1A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This af...
CVE-2025-32912MEDIUM6.5A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause...
CVE-2025-32910MEDIUM6.5A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This iss...
CVE-2025-32909MEDIUM5.3A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 functio...
CVE-2025-2475MEDIUM5.4Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user accoun...
CVE-2025-2424MEDIUM4.3Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now