2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-23534MEDIUM6.5Missing Authorization vulnerability in Mark Winiarski WPLingo wplingo allows Exploiting Incorrectly Configured Access Co...
CVE-2025-22702MEDIUM6.3Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Acces...
CVE-2025-22698MEDIUM6.3Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrect...
CVE-2025-26524MEDIUM5.1This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpo...
CVE-2025-0821MEDIUM6.5Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, ...
CVE-2025-26791MEDIUM6.1DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site sc...
CVE-2025-26789MEDIUM6.9An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access controls allowed li-ad...
CVE-2025-23406MEDIUM5.3Out-of-bounds read vulnerability caused by improper checking of TCP MSS option values exists in Cente middleware TCP/IP ...
CVE-2025-1053MEDIUM4.9Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obt...
CVE-2025-25195MEDIUM4.3Zulip is an open source team chat application. A weekly cron job (added in 50256f48314250978f521ef439cafa704e056539) dem...
CVE-2025-23421MEDIUM6.9An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and ...
CVE-2025-23411MEDIUM6.5mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sens...
CVE-2025-20615MEDIUM6.6The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an a...
CVE-2025-24889MEDIUM4.5The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on ...
CVE-2025-25900MEDIUM4.9A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the username and password parameters at /us...
CVE-2025-25287MEDIUM4.7Lakeus is a simple skin made for MediaWiki. Starting in version 1.0.8 and prior to versions 1.3.1+REL1.39, 1.3.1+REL1.42...
CVE-2025-0426MEDIUM6.2A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthen...
CVE-2025-21701MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: net: avoid race between device unregistration and e...
CVE-2025-26574MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moch Amir Google D...
CVE-2025-26567MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in farjana55 Font Awe...
CVE-2025-26561MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight ...
CVE-2025-26558MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Res...
CVE-2025-26539MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petkivim Embed Goo...
CVE-2025-26538MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Prezi...
CVE-2025-1271MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malici...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now