2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-0236MEDIUM5.3Out-of-bounds vulnerability in slope processing during curve rendering in Generic PCL6 V4 Printer Driver / Generic UFR I...
CVE-2025-0235MEDIUM5.3Out-of-bounds vulnerability due to improper memory release during image rendering in Generic PCL6 V4 Printer Driver / Ge...
CVE-2025-0234MEDIUM5.3Out-of-bounds vulnerability in curve segmentation processing of Generic PCL6 V4 Printer Driver / Generic UFR II V4 Print...
CVE-2025-1091MEDIUM4.3A Broken Authorization schema exists where any authenticated user could download IOA script and configuration files if t...
CVE-2025-25514MEDIUM6.5Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
CVE-2025-27146MEDIUM4.3matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains ...
CVE-2025-27139MEDIUM5.4Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cro...
CVE-2025-25192MEDIUM6.5GLPI is a free asset and IT management software package. Prior to version 10.0.18, a low privileged user can enable debu...
CVE-2025-23024MEDIUM4.3GLPI is a free asset and IT management software package. Starting in version 0.72 and prior to version 10.0.18, an anony...
CVE-2025-21627MEDIUM6.1GLPI is a free asset and IT management software package. In versions prior to 10.0.18, a malicious link can be crafted t...
CVE-2025-21626MEDIUM6.5GLPI is a free asset and IT management software package. Starting in version 0.71 and prior to version 10.0.18, an anony...
CVE-2025-27000MEDIUM5.4Missing Authorization vulnerability in George Pattichis Simple Photo Feed simple-photo-feed allows Exploiting Incorrectl...
CVE-2025-26995MEDIUM5.4Missing Authorization vulnerability in Anton Vanyukov Market Exporter market-exporter allows Exploiting Incorrectly Conf...
CVE-2025-26987MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shabti Kaplan Fron...
CVE-2025-26983MEDIUM4.3Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom ...
CVE-2025-26980MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired...
CVE-2025-26975MEDIUM5.3Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Accessing Functionality N...
CVE-2025-26965MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting I...
CVE-2025-26962MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Easy Cont...
CVE-2025-26960MEDIUM6.5Missing Authorization vulnerability in enituretechnology Small Package Quotes – Unishippers Edition small-package-quotes...
CVE-2025-26952MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Business ...
CVE-2025-26949MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Team Sect...
CVE-2025-26948MEDIUM4.3Missing Authorization vulnerability in NotFound Pie Register Premium. This issue affects Pie Register Premium: from n/a ...
CVE-2025-26947MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Services ...
CVE-2025-26945MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Info Card...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now