2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1467MEDIUM6.1Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth(...
CVE-2025-1586MEDIUM6.1A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as problematic. This vulnerabilit...
CVE-2025-1585MEDIUM5.4A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5. This issue affects the f...
CVE-2025-1584MEDIUM5.3A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8. This vulnerability affects unknown c...
CVE-2025-1579MEDIUM6.1A vulnerability was found in code-projects Blood Bank System 1.0 and classified as problematic. This issue affects some ...
CVE-2025-1577MEDIUM5.4A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by...
CVE-2025-1575MEDIUM5.3A vulnerability classified as problematic has been found in Harpia DiagSystem 12. Affected is an unknown function of the...
CVE-2025-26973MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WarfarePlugins Soc...
CVE-2025-26764MEDIUM6.5Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calc...
CVE-2025-26750MEDIUM6.5Missing Authorization vulnerability in appsbd Vitepos vitepos-lite allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-1557MEDIUM5.3A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The man...
CVE-2025-0953MEDIUM6.1The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a...
CVE-2025-0918MEDIUM6.1The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and...
CVE-2025-1553MEDIUM5.1A vulnerability was found in pankajindevops scale up to 3633544a00245d3df88b6d13d9b3dd0f411be7f6. It has been classified...
CVE-2025-1361MEDIUM5.3The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to...
CVE-2025-27108MEDIUM6.1dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering. In affected versions the use of javascript's `.r...
CVE-2025-25772MEDIUM5.1A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers ...
CVE-2025-25770MEDIUM6.8Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyU...
CVE-2025-25768MEDIUM5.4MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\D...
CVE-2025-25767MEDIUM4.8A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows at...
CVE-2025-25605MEDIUM6.5Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkw...
CVE-2025-25604MEDIUM6.5Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.
CVE-2025-25875MEDIUM6.4A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file ...
CVE-2025-25766MEDIUM4.8An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute ar...
CVE-2025-25765MEDIUM4MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now