2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14379MEDIUM4.4The Testimonials Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version...
CVE-2025-13627MEDIUM4.4The Makesweat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'makesweat_clubid' setting in al...
CVE-2025-12178MEDIUM6.4The SpiceForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spiceforms' short...
CVE-2025-68970MEDIUM5.5Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner...
CVE-2025-68969MEDIUM4.7Multi-thread race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vuln...
CVE-2025-68967MEDIUM5.5Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability ...
CVE-2025-68966MEDIUM5.5Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect...
CVE-2025-68965MEDIUM5.5Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect...
CVE-2025-68964MEDIUM5.5Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect a...
CVE-2025-68963MEDIUM5.3Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may af...
CVE-2025-68962MEDIUM4.7Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner...
CVE-2025-68961MEDIUM4.7Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner...
CVE-2025-68960MEDIUM4.7Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnera...
CVE-2025-68959MEDIUM5.5Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulner...
CVE-2025-68958MEDIUM4.7Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab...
CVE-2025-68957MEDIUM4.7Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab...
CVE-2025-68956MEDIUM4.7Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab...
CVE-2025-68955MEDIUM4.7Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnera...
CVE-2025-68947MEDIUM5.7NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by othe...
CVE-2025-68658MEDIUM4.8Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2025-15056MEDIUM6.1A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This ...
CVE-2025-68925MEDIUM5.3Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't val...
CVE-2025-37179MEDIUM5.3Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data ...
CVE-2025-37177MEDIUM6.5An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors runnin...
CVE-2025-68949MEDIUM5.3n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now