2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-21095MEDIUM6.9Path traversal may lead to arbitrary file download. The score without least privilege principle violation is as calcula...
CVE-2025-1714MEDIUM6.9Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker ...
CVE-2025-1463MEDIUM4.3The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2025-0954MEDIUM6.5The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th...
CVE-2025-22493MEDIUM5.6Secure flag not set and SameSIte was set to Lax in the Foreseer Reporting Software (FRS). Absence of this secure flag co...
CVE-2025-1435MEDIUM6.3The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1...
CVE-2025-1008MEDIUM6.4The Recently Purchased Products For Woo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘view’...
CVE-2025-0990MEDIUM4.3The I Am Gloria plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-27679MEDIUM6.1Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scri...
CVE-2025-27676MEDIUM6.1Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scri...
CVE-2025-27660MEDIUM5.4Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross Site Scri...
CVE-2025-27654MEDIUM6.1Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Cross Site Scri...
CVE-2025-27653MEDIUM6.1Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Preauthenticate...
CVE-2025-27637MEDIUM6.1Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scr...
CVE-2025-1923MEDIUM4.3Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convi...
CVE-2025-1922MEDIUM4.3Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker w...
CVE-2025-1921MEDIUM6.5Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain...
CVE-2025-1917MEDIUM4.3Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker ...
CVE-2025-1967MEDIUM5.1A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. ...
CVE-2025-20002MEDIUM6.9After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information...
CVE-2025-1957MEDIUM5.1A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u...
CVE-2025-26318MEDIUM5.8hb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts...
CVE-2025-1955MEDIUM5.4A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic...
CVE-2025-26202MEDIUM4.3Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4G...
CVE-2025-1969MEDIUM5.3Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a us...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now