2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-25469MEDIUM6.5FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.
CVE-2025-25468MEDIUM6.5FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.
CVE-2025-22921MEDIUM6.5FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/...
CVE-2025-27016MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Drivr Lite...
CVE-2025-27013MEDIUM5.3Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Inco...
CVE-2025-22650MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnens...
CVE-2025-22645MEDIUM5.3Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager real-estate-...
CVE-2025-0622MEDIUM6.4A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related mod...
CVE-2025-26603MEDIUM4.2Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:red...
CVE-2025-26465MEDIUM6.8A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be ...
CVE-2025-21608MEDIUM5.3Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able ...
CVE-2025-26620MEDIUM6.3Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.Acces...
CVE-2025-26058MEDIUM4.2Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or oth...
CVE-2025-22207MEDIUM6.7Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler.
CVE-2025-1414MEDIUM6.5Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2025-1269MEDIUM4.8URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing. Thi...
CVE-2025-1035MEDIUM5.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog...
CVE-2025-0817MEDIUM6.1The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ...
CVE-2025-0521MEDIUM6.1The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in al...
CVE-2025-0981MEDIUM6.1A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a ...
CVE-2025-0864MEDIUM6.1The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Refle...
CVE-2025-0424MEDIUM5.1In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated ...
CVE-2025-0423MEDIUM5.3In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticate...
CVE-2025-0805MEDIUM5.4The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2025-0796MEDIUM4.3The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now