2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12640MEDIUM4.3The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul...
CVE-2025-12776MEDIUM5.4The Report Builder component of the application stores user input directly in a web page and displays it to other users,...
CVE-2025-69255MEDIUM4RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed g...
CVE-2025-69221MEDIUM4.3LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when que...
CVE-2025-69220MEDIUM5.9LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file...
CVE-2025-61939MEDIUM4.4An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authe...
CVE-2025-61782MEDIUM6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2025-58441MEDIUM6.5Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-si...
CVE-2025-66837MEDIUM6.8A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted...
CVE-2025-66686MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with admini...
CVE-2025-61489MEDIUM6.5A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute ar...
CVE-2025-66838MEDIUM6.5In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, a...
CVE-2025-62327MEDIUM4.9In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credenti...
CVE-2025-49335MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in minnur External Media external-media allows Server Side Request Forg...
CVE-2025-6225MEDIUM6.9Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to she...
CVE-2025-15479MEDIUM5.4Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbru...
CVE-2025-46434MEDIUM6.5Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon all...
CVE-2025-46256MEDIUM6.4Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue ...
CVE-2025-69344MEDIUM4.3Missing Authorization vulnerability in themehunk Oneline Lite oneline-lite allows Exploiting Incorrectly Configured Acce...
CVE-2025-69333MEDIUM4.3Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access C...
CVE-2025-47395MEDIUM6.5Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.
CVE-2025-47369MEDIUM5.5Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a ses...
CVE-2025-47344MEDIUM6.4Memory corruption while handling sensor utility operations.
CVE-2025-47337MEDIUM6.7Memory corruption while accessing a synchronization object during concurrent operations.
CVE-2025-47336MEDIUM6.7Memory corruption while performing sensor register read operations.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now