2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-31178MEDIUM6.2A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.
CVE-2025-31176MEDIUM6.2A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.
CVE-2025-30221MEDIUM4.3Pitchfork is a preforking HTTP server for Rack applications. Versions prior to 0.11.0 are vulnerable to HTTP Response He...
CVE-2025-29497MEDIUM6.5libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.
CVE-2025-29496MEDIUM6.5libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerabilit...
CVE-2025-29494MEDIUM6.5libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability al...
CVE-2025-29493MEDIUM6.5libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability ...
CVE-2025-29492MEDIUM6.5libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.
CVE-2025-29491MEDIUM6.5An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a ...
CVE-2025-29490MEDIUM6.5libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability a...
CVE-2025-29489MEDIUM6.5libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.
CVE-2025-29488MEDIUM6.5libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.
CVE-2025-29486MEDIUM6.5libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.
CVE-2025-29485MEDIUM6.5libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allow...
CVE-2025-29483MEDIUM6.5libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.
CVE-2025-22671MEDIUM4.3Missing Authorization vulnerability in Leap13 Disable Elementor Editor Translation disable-elementor-editor-translation ...
CVE-2025-22670MEDIUM6.5Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Exploiting Incor...
CVE-2025-22669MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Cross ...
CVE-2025-22668MEDIUM6.5Missing Authorization vulnerability in AwesomeTOGI Awesome Event Booking awesome-event-booking allows Exploiting Incorre...
CVE-2025-22667MEDIUM4.3Missing Authorization vulnerability in Creative Werk Designs Export Order, Product, Customer & Coupon for WooCommerce to...
CVE-2025-22665MEDIUM4.3Missing Authorization vulnerability in Shakeeb Sadikeen RapidLoad unusedcss allows Exploiting Incorrectly Configured Acc...
CVE-2025-22660MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wolfgang Include M...
CVE-2025-22659MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fo...
CVE-2025-22649MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project ...
CVE-2025-22648MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Blog, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now