2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20158MEDIUM4.4A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticat...
CVE-2025-20153MEDIUM5.3A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote at...
CVE-2025-1465MEDIUM6.6A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the f...
CVE-2025-0968MEDIUM5.3The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2025-0916MEDIUM6.1The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPr...
CVE-2025-1024MEDIUM4.8A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser...
CVE-2025-1007MEDIUM5.3In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace ...
CVE-2025-0865MEDIUM6.5The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3...
CVE-2025-0633MEDIUM5.1Heap-based Buffer Overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows attacker to read out of boun...
CVE-2025-25054MEDIUM6.1Movable Type contains a reflected cross-site scripting vulnerability in the user information edit page. When Multi-Facto...
CVE-2025-24841MEDIUM5.4Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploi...
CVE-2025-22888MEDIUM5.4Movable Type contains a stored cross-site scripting vulnerability in the custom block edit page of MT Block Editor. If e...
CVE-2025-1065MEDIUM6.4The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-22622MEDIUM4.3Age Verification for your checkout page. Verify your customer's identity 1.20.0 was found to be vulnerable. The web appl...
CVE-2025-1447MEDIUM5.3A vulnerability was found in kasuganosoras Pigeon 1.0.177. It has been declared as critical. This vulnerability affects ...
CVE-2025-26624MEDIUM6.8Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.22...
CVE-2025-25474MEDIUM6.5DCMTK v3.6.9+ DEV was discovered to contain a buffer overflow via the component /dcmimgle/diinpxt.h.
CVE-2025-25473MEDIUM5.3FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in ...
CVE-2025-25472MEDIUM5.3A buffer overflow in DCMTK git master v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DCM ...
CVE-2025-25471MEDIUM4.3FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavforma...
CVE-2025-22920MEDIUM5.3A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via...
CVE-2025-22919MEDIUM6.5A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (Do...
CVE-2025-25896MEDIUM5.7A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the destination, netmask, and gateway parame...
CVE-2025-25892MEDIUM5.7A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, dstartip, and dendip p...
CVE-2025-25891MEDIUM5.7A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gatew...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now