2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-26306MEDIUM6.5A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attacke...
CVE-2025-1039MEDIUM6.1The Lenix Elementor Leads addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a URL form field i...
CVE-2025-21106MEDIUM5.5Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Loc...
CVE-2025-1043MEDIUM6.4The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side R...
CVE-2025-1483MEDIUM5.3The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data due...
CVE-2025-1328MEDIUM5.4The Typed JS: A typewriter style animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ty...
CVE-2025-0866MEDIUM6.5The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter i...
CVE-2025-1064MEDIUM5.4The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2025-0897MEDIUM5.4The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2025-27218MEDIUM5.3Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through ...
CVE-2025-24947MEDIUM5.3A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2....
CVE-2025-24946MEDIUM5.3The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attacker...
CVE-2025-23020MEDIUM5.3An issue was discovered in Kwik before 0.10.1. A hash collision vulnerability (in the hash table used to manage connecti...
CVE-2025-1223MEDIUM6.1An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citri...
CVE-2025-1222MEDIUM6.1An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citri...
CVE-2025-0112MEDIUM6.8A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W...
CVE-2025-25947MEDIUM5.5An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_At...
CVE-2025-25946MEDIUM5.5An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specific...
CVE-2025-25945MEDIUM6.5An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_...
CVE-2025-25942MEDIUM6.5An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when proce...
CVE-2025-27090MEDIUM5.3Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all s...
CVE-2025-0677MEDIUM6.4A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to alloc...
CVE-2025-1118MEDIUM4.4A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to re...
CVE-2025-27089MEDIUM4.3Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two o...
CVE-2025-20211MEDIUM6.1A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now