2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-0630MEDIUM6.5Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (L...
CVE-2025-0509MEDIUM6.8A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with anoth...
CVE-2025-24373MEDIUM6.5woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF inv...
CVE-2025-0451MEDIUM6.3Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who con...
CVE-2025-0445MEDIUM5.4Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corru...
CVE-2025-0444MEDIUM6.3Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap cor...
CVE-2025-23059MEDIUM4.9A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directori...
CVE-2025-24598MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mails...
CVE-2025-22730MEDIUM6.5Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Acces...
CVE-2025-22697MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon...
CVE-2025-22696MEDIUM5.4Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Docu...
CVE-2025-22675MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Alert Box...
CVE-2025-22674MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Produc...
CVE-2025-22664MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak...
CVE-2025-22662MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPuls...
CVE-2025-22653MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv Music Pres...
CVE-2025-22643MEDIUM4.3Missing Authorization vulnerability in famethemes OnePress onepress allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-22642MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtowebsites Dynami...
CVE-2025-22641MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prem Tiwari FM Not...
CVE-2025-22206MEDIUM4.7A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.2 for Joomla allows authenticated attackers (admi...
CVE-2025-0825MEDIUM5.3cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null...
CVE-2025-1019MEDIUM4.3The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be l...
CVE-2025-1018MEDIUM5.3The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have b...
CVE-2025-1015MEDIUM5.4The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and exp...
CVE-2025-1013MEDIUM6.5A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have result...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now