2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14384MEDIUM4.3The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ...
CVE-2025-12641MEDIUM6.5The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to mis...
CVE-2025-68671MEDIUM4.8lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not ...
CVE-2025-70891MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user...
CVE-2025-70890MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker...
CVE-2025-67025MEDIUM6.1Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code ...
CVE-2025-65368MEDIUM6.1SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output.
CVE-2025-60011MEDIUM6.9An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne...
CVE-2025-60007MEDIUM6.8A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX...
CVE-2025-59961MEDIUM6.8An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Ne...
CVE-2025-59959MEDIUM6.8An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Jun...
CVE-2025-52987MEDIUM6.1A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insig...
CVE-2025-65349MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELES...
CVE-2025-15265MEDIUM6.1An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside ...
CVE-2025-70303MEDIUM5.5A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-70302MEDIUM5.5A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service ...
CVE-2025-13844MEDIUM5.3CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious ...
CVE-2025-70299MEDIUM6.5A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS...
CVE-2025-70310MEDIUM5.5A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) vi...
CVE-2025-70309MEDIUM5.5A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (D...
CVE-2025-70305MEDIUM5.5A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafte...
CVE-2025-67078MEDIUM6.1Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary...
CVE-2025-67083MEDIUM5.3Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the ...
CVE-2025-67082MEDIUM6.5An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" para...
CVE-2025-67081MEDIUM4.9An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now