2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14001MEDIUM5.4The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability ...
CVE-2025-68657MEDIUM6.4Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hi...
CVE-2025-68656MEDIUM6.8Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_r...
CVE-2025-68471MEDIUM6.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ...
CVE-2025-68468MEDIUM6.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ...
CVE-2025-68276MEDIUM5.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 ...
CVE-2025-68622MEDIUM6.8Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in ...
CVE-2025-66689MEDIUM6.5A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitra...
CVE-2025-67813MEDIUM5.3Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communica...
CVE-2025-66939MEDIUM5.4Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via ...
CVE-2025-65553MEDIUM6.5D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attac...
CVE-2025-41003MEDIUM5.1Imaster's Patient Record Management System contains a stored Cross-Site Scripting (XSS) vulnerability in the endpoint ‘/...
CVE-2025-40978MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack o...
CVE-2025-40977MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation ...
CVE-2025-40976MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's TicketGo, consisting of a lack of proper validation of user ...
CVE-2025-40975MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's HRMGo, consisting of a lack of proper validation of user inp...
CVE-2025-14579MEDIUM4.8The Quiz Maker WordPress plugin before 6.7.0.89 does not sanitise and escape some of its settings, which could allow hig...
CVE-2025-69275MEDIUM6.1Dependency on Vulnerable Third-Party Component vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows DOM...
CVE-2025-69268MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Broadcom DX...
CVE-2025-69267MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectru...
CVE-2025-13393MEDIUM4.3The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ...
CVE-2025-12379MEDIUM6.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-14555MEDIUM6.4The Countdown Timer – Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2025-15504MEDIUM5.5A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::pa...
CVE-2025-14506MEDIUM6.4The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now