2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2797MEDIUM5.4The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-3214MEDIUM5.3A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability i...
CVE-2025-2836MEDIUM6.4The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2025-2279MEDIUM5.9The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting...
CVE-2025-2159MEDIUM5.1Stored XSS in Desktop UI in M-Files Server Admin tool before version 25.3.14681.7 on Windows allows authenticated local ...
CVE-2025-3191MEDIUM6.1All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button whi...
CVE-2025-3203MEDIUM5.3A vulnerability classified as problematic was found in Tenda W18E 16.01.0.11. Affected by this vulnerability is the func...
CVE-2025-3198MEDIUM5.5A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability i...
CVE-2025-3196MEDIUM5.5A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the ...
CVE-2025-26401MEDIUM6.5Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authen...
CVE-2025-25061MEDIUM5.8Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, whi...
CVE-2025-24317MEDIUM5.3Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, whi...
CVE-2025-24310MEDIUM4.3Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote...
CVE-2025-29796MEDIUM4.7User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker ...
CVE-2025-25001MEDIUM4.3Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ...
CVE-2025-0279MEDIUM4.3HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal...
CVE-2025-0278MEDIUM4.3HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reve...
CVE-2025-31486MEDIUM5.3Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By ...
CVE-2025-31483MEDIUM4.8Miniflux is a feed reader. Due to a weak Content Security Policy on the /proxy/* route, an attacker can bypass the CSP o...
CVE-2025-31127MEDIUM5.3Element X Android is a Matrix Android Client provided by element.io. In Element X Android versions between 0.4.16 and 25...
CVE-2025-31126MEDIUM5.3Element X iOS is a Matrix iOS Client provided by Element. In Element X iOS version between 1.6.13 and 25.03.7, the entit...
CVE-2025-3169MEDIUM5A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unkno...
CVE-2025-3165MEDIUM5.3A vulnerability classified as critical has been found in thu-pacman chitu 0.1.0. This affects the function torch.load of...
CVE-2025-3157MEDIUM4.8A vulnerability was found in Intelbras WRN 150 1.0.15_pt_ITB01. It has been rated as problematic. This issue affects som...
CVE-2025-32053MEDIUM6.5A flaw was found in libsoup. A vulnerability in sniff_feed_or_html() and skip_insignificant_space() functions may lead t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now