2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54814MEDIUM5.4A reflected cross-site scripting (xss) vulnerability exists in the modifyAutopurgeFilter functionality of MedDream PACS ...
CVE-2025-54778MEDIUM5.4A reflected cross-site scripting (xss) vulnerability exists in the existingUser functionality of MedDream PACS Premium 7...
CVE-2025-54495MEDIUM5.4A reflected cross-site scripting (xss) vulnerability exists in the emailfailedjob functionality of MedDream PACS Premium...
CVE-2025-54157MEDIUM5.4A reflected cross-site scripting (xss) vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premiu...
CVE-2025-53854MEDIUM5.4A reflected cross-site scripting (xss) vulnerability exists in the modifyHL7Route functionality of MedDream PACS Premium...
CVE-2025-53707MEDIUM6.1A reflected cross-site scripting (xss) vulnerability exists in the modifyTranscript functionality of MedDream PACS Premi...
CVE-2025-53516MEDIUM6.1A reflected cross-site scripting (xss) vulnerability exists in the downloadZip functionality of MedDream PACS Premium 7....
CVE-2025-46270MEDIUM5.4A reflected cross-site scripting (xss) vulnerability exists in the fetchPriorStudies functionality of MedDream PACS Prem...
CVE-2025-44000MEDIUM6.1A reflected cross-site scripting (xss) vulnerability exists in the sendOruReport functionality of MedDream PACS Premium ...
CVE-2025-36556MEDIUM5.4A reflected cross-site scripting (xss) vulnerability exists in the ldapUser functionality of MedDream PACS Premium 7.3.6...
CVE-2025-15043MEDIUM5.4The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t...
CVE-2025-13925MEDIUM4.9IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged ...
CVE-2025-41081MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in IsMyGym by Zuinq Studio. This vulnerability allows an attacker to ...
CVE-2025-41025MEDIUM5.4Stored Cross-Site Scripting (XSS) in Poultry Farm Management System v1.0 due to the lack of proper validation of user in...
CVE-2025-41024MEDIUM5.4Stored Cross-Site Scripting (XSS) in Poultry Farm Management System v1.0 due to the lack of proper validation of user in...
CVE-2025-40679MEDIUM5.1HTML Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation ...
CVE-2025-40644MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in Riftzilla's QRGen. This vulnerability allows an attavker to execut...
CVE-2025-14369MEDIUM5.5dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting th...
CVE-2025-41084MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are ...
CVE-2025-41768MEDIUM5.5An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to...
CVE-2025-66523MEDIUM6.1URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. Th...
CVE-2025-12573MEDIUM6.5The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, al...
CVE-2025-14348MEDIUM5.3The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo...
CVE-2025-14798MEDIUM5.3The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, a...
CVE-2025-14351MEDIUM5.3The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a miss...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now