2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61549MEDIUM6.1Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu B...
CVE-2025-61547MEDIUM6.8Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 1...
CVE-2025-67091MEDIUM6.5An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL....
CVE-2025-67090MEDIUM5.1The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL...
CVE-2025-67603MEDIUM5.1A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This is...
CVE-2025-66002MEDIUM6.9An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ...
CVE-2025-4596MEDIUM5.3Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging t...
CVE-2025-8307MEDIUM5.9Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec...
CVE-2025-8306MEDIUM5.1Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec...
CVE-2025-69169MEDIUM5.4Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Down...
CVE-2025-68875MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming...
CVE-2025-68867MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anibalwainstein Ef...
CVE-2025-67926MEDIUM6.5Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Confi...
CVE-2025-67919MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting ...
CVE-2025-67917MEDIUM6.5Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-67913MEDIUM6.5Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionali...
CVE-2025-22726MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request For...
CVE-2025-15079MEDIUM5.3When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenl...
CVE-2025-14984MEDIUM6.4The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all version...
CVE-2025-14819MEDIUM5.3When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option...
CVE-2025-14524MEDIUM5.3When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a s...
CVE-2025-14017MEDIUM6.3When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadver...
CVE-2025-13034MEDIUM5.9When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the pu...
CVE-2025-13679MEDIUM6.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data d...
CVE-2025-14275MEDIUM6.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now