2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-29780MEDIUM5.8Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret ...
CVE-2025-29779MEDIUM5.4Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret ...
CVE-2025-26312MEDIUM5.3SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter.
CVE-2025-27606MEDIUM4.6Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain...
CVE-2025-1888MEDIUM4.6The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS)....
CVE-2025-25873MEDIUM5.5Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges...
CVE-2025-25872MEDIUM5.5An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
CVE-2025-29032MEDIUM5.9Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVE-2025-26626MEDIUM6.5The GLPI Inventory Plugin handles various types of tasks for GLPI agents for the GLPI asset and IT management software p...
CVE-2025-1507MEDIUM5.3The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due...
CVE-2025-1526MEDIUM5.4The DethemeKit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the De Product Displa...
CVE-2025-2166MEDIUM6.1The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cro...
CVE-2025-1528MEDIUM4.3The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch...
CVE-2025-1285MEDIUM5.3The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capab...
CVE-2025-0955MEDIUM5.3The VidoRev Extensions plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th...
CVE-2025-30022MEDIUM6.8CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.
CVE-2025-25363MEDIUM6.5An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira D...
CVE-2025-29768MEDIUM4.4Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to...
CVE-2025-28011MEDIUM6.1A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management...
CVE-2025-27103MEDIUM6.5DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the ...
CVE-2025-24974MEDIUM6.5DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated use...
CVE-2025-1767MEDIUM6.5This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other p...
CVE-2025-28015MEDIUM5.3A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and...
CVE-2025-28010MEDIUM5.4A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenti...
CVE-2025-25625MEDIUM5.4A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fs...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now