2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1949MEDIUM6.1A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown proc...
CVE-2025-27402MEDIUM4.6Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF ...
CVE-2025-27401MEDIUM4.6Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of...
CVE-2025-27156MEDIUM5.4Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing featu...
CVE-2025-27155MEDIUM6.1Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The ...
CVE-2025-27150MEDIUM6.5Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect...
CVE-2025-26182MEDIUM6.5An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageControl...
CVE-2025-26091MEDIUM4.6A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remot...
CVE-2025-26320MEDIUM6.5t0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address paramet...
CVE-2025-1425MEDIUM4.7A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file...
CVE-2025-27426MEDIUM5.4Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. Thi...
CVE-2025-27425MEDIUM4.3Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the ...
CVE-2025-27424MEDIUM4.3Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page. This vul...
CVE-2025-1938MEDIUM6.5Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs...
CVE-2025-1935MEDIUM4.3A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerabilit...
CVE-2025-1934MEDIUM6.5It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering ga...
CVE-2025-22226MEDIUM6VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGF...
CVE-2025-0958MEDIUM6.3The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access to functionality in all ...
CVE-2025-0370MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-26849MEDIUM4.3There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be use...
CVE-2025-0512MEDIUM5.4The Structured Content (JSON-LD) #wpsc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2025-0433MEDIUM5.4The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ...
CVE-2025-27521MEDIUM5.5Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vul...
CVE-2025-0359MEDIUM5.5During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Appli...
CVE-2025-1905MEDIUM6.1A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now