2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13182MEDIUM4.8A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/...
CVE-2025-63701MEDIUM6.8A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.2078...
CVE-2025-13181MEDIUM4.8A vulnerability was determined in pojoin h3blog 1.0. The affected element is an unknown function of the file /admin/cms/...
CVE-2025-13180MEDIUM5.4A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 2025032...
CVE-2025-13179MEDIUM6.5A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20...
CVE-2025-63291MEDIUM5.4When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify ...
CVE-2025-13178MEDIUM5.4A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file ...
CVE-2025-13174MEDIUM6.3A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this vulnerability is the function d...
CVE-2025-63830MEDIUM6.1CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted...
CVE-2025-63725MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php.
CVE-2025-63724MEDIUM6SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php.
CVE-2025-54562MEDIUM4.3A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows ...
CVE-2025-54561MEDIUM4.3An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1...
CVE-2025-54348MEDIUM6.5A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version...
CVE-2025-54340MEDIUM4.1A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a B...
CVE-2025-4618MEDIUM4.4A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated no...
CVE-2025-8870MEDIUM5.6On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the devic...
CVE-2025-12149MEDIUM6In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, whe...
CVE-2025-10018MEDIUM4.8QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admi...
CVE-2025-11981MEDIUM4.9The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parame...
CVE-2025-11794MEDIUM4.9Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows sy...
CVE-2025-55073MEDIUM5.3Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between ...
CVE-2025-41436MEDIUM4.3Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regu...
CVE-2025-11776MEDIUM4.3Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to disc...
CVE-2025-13160MEDIUM6.9IQ-Support developed by IQ Service International has a Exposure of Sensitive Information vulnerability, allowing unauthe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now