2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4596MEDIUM5.3Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging t...
CVE-2025-8307MEDIUM5.9Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec...
CVE-2025-8306MEDIUM5.1Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec...
CVE-2025-69169MEDIUM5.4Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Down...
CVE-2025-68875MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming...
CVE-2025-68867MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anibalwainstein Ef...
CVE-2025-67926MEDIUM6.5Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Confi...
CVE-2025-67919MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting ...
CVE-2025-67917MEDIUM6.5Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-67913MEDIUM6.5Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionali...
CVE-2025-22726MEDIUM6.4Server-Side Request Forgery (SSRF) vulnerability in _nK nK Themes Helper nk-themes-helper allows Server Side Request For...
CVE-2025-15079MEDIUM5.3When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenl...
CVE-2025-14984MEDIUM6.4The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all version...
CVE-2025-14819MEDIUM5.3When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option,...
CVE-2025-14524MEDIUM5.3When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a s...
CVE-2025-14017MEDIUM6.3When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadver...
CVE-2025-13034MEDIUM5.9When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool, curl should check the p...
CVE-2025-13679MEDIUM6.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data d...
CVE-2025-14275MEDIUM6.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2025-12640MEDIUM4.3The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul...
CVE-2025-12776MEDIUM5.4The Report Builder component of the application stores user input directly in a web page and displays it to other users,...
CVE-2025-69255MEDIUM4RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed g...
CVE-2025-69221MEDIUM4.3LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when que...
CVE-2025-69220MEDIUM5.9LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file...
CVE-2025-61939MEDIUM4.4An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now