2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14976MEDIUM5.4The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict...
CVE-2025-14948MEDIUM5.3The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-14943MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure...
CVE-2025-65090MEDIUM5.3XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights ...
CVE-2025-61676MEDIUM4.8October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti...
CVE-2025-61674MEDIUM4.8October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripti...
CVE-2025-68470MEDIUM6.5React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path ...
CVE-2025-46299MEDIUM4.3A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 ...
CVE-2025-46298MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, mac...
CVE-2025-46297MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be a...
CVE-2025-46286MEDIUM4.3A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a ...
CVE-2025-60538MEDIUM6.5A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a bru...
CVE-2025-51626MEDIUM6.5SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.
CVE-2025-67811MEDIUM6.5Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient in...
CVE-2025-67810MEDIUM6.5In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST req...
CVE-2025-66715MEDIUM6.5A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DL...
CVE-2025-67004MEDIUM6.5** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via t...
CVE-2025-67282MEDIUM5.4In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileg...
CVE-2025-67281MEDIUM5.4In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and ...
CVE-2025-67280MEDIUM5.4In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a...
CVE-2025-67279MEDIUM5.3An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi...
CVE-2025-67278MEDIUM6.5An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi...
CVE-2025-46676MEDIUM4.9Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-46644MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-46643MEDIUM4.4Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now