2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-0362MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.1...
CVE-2025-32395MEDIUM6Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of ...
CVE-2025-32391MEDIUM4.6HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.3, a malicious SVG file ...
CVE-2025-2469MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. T...
CVE-2025-29088MEDIUM5.5In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial ...
CVE-2025-30148MEDIUM5.4Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. Prior to 5.3.23, bad actor with access to e...
CVE-2025-2408MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17.9 before 17.9.6, and 17...
CVE-2025-25197MEDIUM5.4Silverstripe Elemental extends a page type to swap the content area for a list of manageable elements to compose a page ...
CVE-2025-31411MEDIUM5.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aribhour Linet ERP-Wooco...
CVE-2025-22374MEDIUM6A Server-Side Request Forgery (SSRF) vulnerability was discovered in the videx-legacy-ssl web service of Videx’s CyberAu...
CVE-2025-27081MEDIUM6.8A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a...
CVE-2025-32282MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ShareThis ShareThis Dashboard for Google Analytics googleanalytics.Th...
CVE-2025-32275MEDIUM5.3Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker survey-maker allows Identity Spoofing.This issue...
CVE-2025-32260MEDIUM5.3Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor.This issue affects Deth...
CVE-2025-32259MEDIUM5.3Missing Authorization vulnerability in Alimir WP ULike wp-ulike.This issue affects WP ULike: from n/a through <= 4.7.9.1...
CVE-2025-32244MEDIUM6.5Missing Authorization vulnerability in QuantumCloud SEO Help seo-help allows Exploiting Incorrectly Configured Access Co...
CVE-2025-32243MEDIUM6.5Missing Authorization vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Exploiting Inco...
CVE-2025-32242MEDIUM6.5Missing Authorization vulnerability in Hive Support Hive Support hive-support allows Accessing Functionality Not Properl...
CVE-2025-32240MEDIUM6.5Missing Authorization vulnerability in wpvsingh Site Notify site-notify allows Exploiting Incorrectly Configured Access ...
CVE-2025-32236MEDIUM4.3Missing Authorization vulnerability in Vagonic Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrang...
CVE-2025-32230MEDIUM4.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Themeum Tutor LMS tutor.T...
CVE-2025-32228MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah Ai Image Alt Text...
CVE-2025-32227MEDIUM4.3Authentication Bypass by Spoofing vulnerability in Asgaros Asgaros Forum asgaros-forum allows Identity Spoofing.This iss...
CVE-2025-32221MEDIUM5.4Missing Authorization vulnerability in Spider Themes EazyDocs eazydocs allows Exploiting Incorrectly Configured Access C...
CVE-2025-32216MEDIUM6.4Missing Authorization vulnerability in Spider Themes Spider Elements spider-elements allows Exploiting Incorrectly Confi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now