2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11759MEDIUM4.3The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2025-62223MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker ...
CVE-2025-14052MEDIUM6.5A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function get...
CVE-2025-66563MEDIUM6.1Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user in...
CVE-2025-66561MEDIUM5.4SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting ...
CVE-2025-6946MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi...
CVE-2025-65900MEDIUM6.5Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due...
CVE-2025-65899MEDIUM5.3Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application retu...
CVE-2025-1910MEDIUM6.3The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to e...
CVE-2025-13940MEDIUM5.5An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fir...
CVE-2025-13939MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13938MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13937MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-13936MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2025-12986MEDIUM6When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of service tri...
CVE-2025-66574MEDIUM5.4TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint,...
CVE-2025-66572MEDIUM6.9Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthe...
CVE-2025-65959MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a St...
CVE-2025-65806MEDIUM4.3The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a ...
CVE-2025-63499MEDIUM6.1Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
CVE-2025-12996MEDIUM4.1Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext ...
CVE-2025-12994MEDIUM5.3Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an ...
CVE-2025-63361MEDIUM5.7Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00...
CVE-2025-59788MEDIUM5.4Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions bef...
CVE-2025-14013MEDIUM4.8A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now