2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-27584MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS...
CVE-2025-25953MEDIUM6.5Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure ...
CVE-2025-25952MEDIUM6.5An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solution...
CVE-2025-25949MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS...
CVE-2025-1842MEDIUM5.3A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302. This vuln...
CVE-2025-27579MEDIUM5.4In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka st...
CVE-2025-1836MEDIUM5.3A vulnerability was found in Incorta 2023.4.3. It has been classified as problematic. Affected is an unknown function of...
CVE-2025-1835MEDIUM6.3A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the fu...
CVE-2025-1830MEDIUM4.8A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown p...
CVE-2025-1817MEDIUM5.4A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown cod...
CVE-2025-1816MEDIUM5.3A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This ...
CVE-2025-1813MEDIUM6.5A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unk...
CVE-2025-1810MEDIUM5.3A vulnerability was found in Pixsoft Vivaz 6.0.11. It has been classified as problematic. Affected is an unknown functio...
CVE-2025-1807MEDIUM5.1A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknow...
CVE-2025-1806MEDIUM5.3A vulnerability, which was classified as problematic, has been found in Eastnets PaymentSafe 2.5.26.0. Affected by this ...
CVE-2025-1799MEDIUM6.3A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAc...
CVE-2025-1797MEDIUM6.3A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun...
CVE-2025-1491MEDIUM6.4The WP Posts Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play_timeout’ para...
CVE-2025-1404MEDIUM5.3The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data...
CVE-2025-1291MEDIUM6.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2025-1730MEDIUM6.5The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includi...
CVE-2025-1502MEDIUM5.3The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit...
CVE-2025-1459MEDIUM5.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Embedded Video(...
CVE-2025-0820MEDIUM6.4The Clicface Trombi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nom’ parameter in all ver...
CVE-2025-1780MEDIUM4.3The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now