2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-69267MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectru...
CVE-2025-13393MEDIUM4.3The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ...
CVE-2025-12379MEDIUM6.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-14555MEDIUM6.4The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2025-15504MEDIUM5.5A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::pa...
CVE-2025-14506MEDIUM6.4The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block...
CVE-2025-14976MEDIUM5.4The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict...
CVE-2025-14948MEDIUM5.3The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-14943MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure...
CVE-2025-65090MEDIUM5.3XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights ...
CVE-2025-61676MEDIUM4.8October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti...
CVE-2025-61674MEDIUM4.8October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti...
CVE-2025-68470MEDIUM6.5React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path ...
CVE-2025-46299MEDIUM4.3A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 ...
CVE-2025-46298MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, mac...
CVE-2025-46297MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be a...
CVE-2025-46286MEDIUM4.3A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a ...
CVE-2025-60538MEDIUM6.5A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a bru...
CVE-2025-51626MEDIUM6.5SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.
CVE-2025-67811MEDIUM6.5Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient in...
CVE-2025-67810MEDIUM6.5In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST req...
CVE-2025-66715MEDIUM6.5A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DL...
CVE-2025-67004MEDIUM6.5** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via t...
CVE-2025-67282MEDIUM5.4In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileg...
CVE-2025-67281MEDIUM5.4In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now