2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64750MEDIUM4.5SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.3.5 and SingularityPRO 4....
CVE-2025-52622MEDIUM5.4The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the applicatio...
CVE-2025-65186MEDIUM6.1Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page con...
CVE-2025-64070MEDIUM5.4Sourcecodester Student Grades Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the Add New Subject ...
CVE-2025-65187MEDIUM6.1A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authentica...
CVE-2025-63872MEDIUM6.1DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated ...
CVE-2025-59704MEDIUM4.6Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (...
CVE-2025-58113MEDIUM6.5An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.7.3.401...
CVE-2025-13877MEDIUM5.6A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the ...
CVE-2025-13372MEDIUM4.3An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to ...
CVE-2025-12630MEDIUM4.9The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability ch...
CVE-2025-59705MEDIUM6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (...
CVE-2025-59701MEDIUM4.1Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (...
CVE-2025-59699MEDIUM6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (...
CVE-2025-59698MEDIUM6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (...
CVE-2025-59694MEDIUM6.8The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patch...
CVE-2025-13875MEDIUM6.3A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file ...
CVE-2025-13505MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Neutralization of ...
CVE-2025-41086MEDIUM6.5Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be gener...
CVE-2025-41066MEDIUM5.3Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the ex...
CVE-2025-13731MEDIUM6.4The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2025-41012MEDIUM5.3Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attack...
CVE-2025-40700MEDIUM6.1Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScri...
CVE-2025-13090MEDIUM4.9The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up t...
CVE-2025-41743MEDIUM4Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unpriv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now