2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14331MEDIUM6.5Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 11...
CVE-2025-14311MEDIUM6.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JMRI.This issue affects ...
CVE-2025-14284MEDIUM6.1Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanit...
CVE-2025-13642MEDIUM5.4The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2025-13070MEDIUM6.6The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to gener...
CVE-2025-13031MEDIUM5.9The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which c...
CVE-2025-12558MEDIUM4.3The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2025-10876MEDIUM5.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft...
CVE-2025-10573MEDIUM6.1Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute ...
CVE-2025-66491MEDIUM5.9Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in...
CVE-2025-66490MEDIUM6.5Traefik is an HTTP reverse proxy and load balancer. For versions prior to 2.11.32 and 2.11.31 through 3.6.2, requests us...
CVE-2025-66470MEDIUM6.1NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.inter...
CVE-2025-66469MEDIUM6.1NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to Reflected XSS through its ui.add_css,...
CVE-2025-66202MEDIUM6.5Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated a...
CVE-2025-65962MEDIUM4.3Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Comm...
CVE-2025-64760MEDIUM4.3Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Comm...
CVE-2025-64499MEDIUM5.4Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon...
CVE-2025-64498MEDIUM4.3Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versio...
CVE-2025-64497MEDIUM6.5Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.17624313...
CVE-2025-36140MEDIUM6.5IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods...
CVE-2025-64650MEDIUM6.5IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.
CVE-2025-62408MEDIUM5.9c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts whe...
CVE-2025-36017MEDIUM6.5IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive in...
CVE-2025-36015MEDIUM6.5IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated us...
CVE-2025-33111MEDIUM4.3IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of te...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now