2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-27144MEDIUM6.6Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including sup...
CVE-2025-27143MEDIUM6.1Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is v...
CVE-2025-27141MEDIUM6.5Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Sta...
CVE-2025-27137MEDIUM4.4Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software ...
CVE-2025-26532MEDIUM4.3Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
CVE-2025-26531MEDIUM5.3Insufficient capability checks made it possible to disable badges a user does not have permission to access.
CVE-2025-26530MEDIUM6.1The question bank filter required additional sanitizing to prevent a reflected XSS risk.
CVE-2025-26529MEDIUM6.1Description information displayed in the site administration live log required additional sanitizing to prevent a store...
CVE-2025-26528MEDIUM6.1The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
CVE-2025-26527MEDIUM5.3Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block...
CVE-2025-26526MEDIUM6.5Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of respo...
CVE-2025-27112MEDIUM6.5Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to vers...
CVE-2025-25460MEDIUM4.8A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This...
CVE-2025-27357MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Musa AVCI Önceki Yazı Link onceki-yazi-linki allows Cross Site Reques...
CVE-2025-27356MEDIUM5.4Missing Authorization vulnerability in Hardik Sticky Header On Scroll sticky-header-on-scroll allows Exploiting Incorrec...
CVE-2025-27353MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Bob Namaste! LMS namaste-lms allows Cross Site Request Forgery.This i...
CVE-2025-27351MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpertBusinessSear...
CVE-2025-27349MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nurelm Get Posts n...
CVE-2025-27348MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel WP Social S...
CVE-2025-27347MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techmix Direct Che...
CVE-2025-27344MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in filipstepanov Phee's LinkPreview linkpreview allows Cross Site Reques...
CVE-2025-27342MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in josesan WooCommerce Recargo de Equivalencia woo-recargo-de-equivalenc...
CVE-2025-27341MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in afzal_du Reactive ...
CVE-2025-27340MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site ...
CVE-2025-27339MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength minimum-password-strength all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now