2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62233MEDIUM6.3Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache Dolphi...
CVE-2025-11762MEDIUM4.3The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2025-66286MEDIUM4.7An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS ...
CVE-2025-13763MEDIUM5.7Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application ...
CVE-2025-62110MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Resc...
CVE-2025-62104MEDIUM4.3Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Con...
CVE-2025-10549MEDIUM5.1EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the in...
CVE-2025-6016MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and ...
CVE-2025-3922MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2025-0186MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2025-58922MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affect...
CVE-2025-41011MEDIUM6.1HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the vic...
CVE-2025-31981MEDIUM5.3HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, al...
CVE-2025-1241MEDIUM4.9Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize...
CVE-2025-10354MEDIUM5.1Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execu...
CVE-2025-66954MEDIUM6.5A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to...
CVE-2025-66335MEDIUM5.3Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context han...
CVE-2025-13480MEDIUM6.5Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only re...
CVE-2025-70795MEDIUM5.5STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT...
CVE-2025-46641MEDIUM6.6Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont...
CVE-2025-15622MEDIUM6.2Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals ...
CVE-2025-54510MEDIUM5.9A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with admi...
CVE-2025-43937MEDIUM6.6Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerab...
CVE-2025-43935MEDIUM4.4Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A hi...
CVE-2025-43883MEDIUM4.1Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vuln...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now