2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15437MEDIUM5.4A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variabl...
CVE-2025-14072MEDIUM5.3The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the...
CVE-2025-13456MEDIUM6.1The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the...
CVE-2025-13153MEDIUM6.1The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting...
CVE-2025-12685MEDIUM6.5The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthentica...
CVE-2025-14047MEDIUM5.3The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User ...
CVE-2025-15419MEDIUM5.5A weakness has been identified in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_ses...
CVE-2025-15418MEDIUM5.5A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function ogs_gtp2_pars...
CVE-2025-15417MEDIUM5.5A vulnerability was identified in Open5GS up to 2.7.6. Affected is the function sgwc_s11_handle_create_session_request o...
CVE-2025-15416MEDIUM5.4A vulnerability was found in xnx3 wangmarket up to 6.4. This affects an unknown function of the file /siteVar/save.do of...
CVE-2025-15415MEDIUM5.4A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the fil...
CVE-2025-15414MEDIUM4.7A flaw has been found in go-sonic sonic up to 1.1.4. The affected element is the function FetchTheme of the file service...
CVE-2025-68273MEDIUM5.3Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure ...
CVE-2025-48768MEDIUM6.5Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX...
CVE-2025-14627MEDIUM6.4The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forger...
CVE-2025-14428MEDIUM4.3The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin f...
CVE-2025-66023MEDIUM4.9NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.5 have a Heap-Use-After-Fre...
CVE-2025-13820MEDIUM5.3The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provid...
CVE-2025-69413MEDIUM5.3In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username e...
CVE-2025-67711MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67710MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67709MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67708MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67707MEDIUM5.6ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem...
CVE-2025-67706MEDIUM5.6ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now