2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-56451MEDIUM6.1Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue paramete...
CVE-2025-69581MEDIUM5.5An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user i...
CVE-2025-51602MEDIUM4.8mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01...
CVE-2025-43904MEDIUM4.2In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user ...
CVE-2025-43508MEDIUM5.5A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able ...
CVE-2025-24531MEDIUM6.7In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as a...
CVE-2025-24089MEDIUM5.3A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app ...
CVE-2025-29943MEDIUM4.6Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU ...
CVE-2025-15104MEDIUM5.3Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arb...
CVE-2025-14435MEDIUM6.5Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API er...
CVE-2025-14822MEDIUM6.5Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authentica...
CVE-2025-14757MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions ...
CVE-2025-14375MEDIUM6.1The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Reflec...
CVE-2025-14853MEDIUM4.3The LEAV Last Email Address Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions <= 1....
CVE-2025-14793MEDIUM5The DK PDF – WordPress PDF Generator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u...
CVE-2025-15527MEDIUM4.3The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 ...
CVE-2025-15526MEDIUM5.3The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includi...
CVE-2025-15370MEDIUM4.3The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D...
CVE-2025-14982MEDIUM4.3The Booking Calendar plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Exposu...
CVE-2025-14384MEDIUM4.3The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ...
CVE-2025-12641MEDIUM6.5The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to mis...
CVE-2025-68671MEDIUM4.8lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not ...
CVE-2025-70891MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user...
CVE-2025-70890MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker...
CVE-2025-67025MEDIUM6.1Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now