2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65368MEDIUM6.1SparkyFitness v0.15.8.2 is vulnerable to Cross Site Scripting (XSS) via user input and LLM output.
CVE-2025-60011MEDIUM6.9An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne...
CVE-2025-60007MEDIUM6.8A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX...
CVE-2025-59961MEDIUM6.8An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Ne...
CVE-2025-59959MEDIUM6.8An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Jun...
CVE-2025-52987MEDIUM6.1A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insig...
CVE-2025-65349MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability in Web management interface in Each Italy Wireless Mini Router WIRELES...
CVE-2025-15265MEDIUM6.1An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside ...
CVE-2025-70303MEDIUM5.5A heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-70302MEDIUM5.5A heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service ...
CVE-2025-13844MEDIUM5.3CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious ...
CVE-2025-70299MEDIUM6.5A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS...
CVE-2025-70310MEDIUM5.5A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) vi...
CVE-2025-70309MEDIUM5.5A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (D...
CVE-2025-70305MEDIUM5.5A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafte...
CVE-2025-67078MEDIUM6.1Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary...
CVE-2025-67083MEDIUM5.3Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the ...
CVE-2025-67082MEDIUM6.5An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" para...
CVE-2025-67081MEDIUM4.9An SQL injection vulnerability in Itflow through 25.06 has been identified in the "role_id" parameter when editing a pro...
CVE-2025-13859MEDIUM6.4The AffiliateX – Amazon Affiliate Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-12895MEDIUM5.3The Kalium 3 | Creative WordPress & WooCommerce Theme theme for WordPress is vulnerable to unauthorized email sending du...
CVE-2025-14448MEDIUM5.4The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Multiple Chec...
CVE-2025-13454MEDIUM6.8A potential vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user t...
CVE-2025-13453MEDIUM5.1A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read...
CVE-2025-13154MEDIUM6.8An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now