2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12366MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object...
CVE-2025-12089MEDIUM6.5The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient...
CVE-2025-64716MEDIUM5.1Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap...
CVE-2025-64711MEDIUM5.4PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior...
CVE-2025-64710MEDIUM5.3Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-s...
CVE-2025-64707MEDIUM5.4Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve...
CVE-2025-64705MEDIUM4.3Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve...
CVE-2025-64517MEDIUM4.4sudo-rs is a memory safe implementation of sudo and su written in Rust. With `Defaults targetpw` (or `Defaults rootpw`) ...
CVE-2025-64482MEDIUM4.6Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Editio...
CVE-2025-64429MEDIUM6.5DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting w...
CVE-2025-63645MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application'...
CVE-2025-33119MEDIUM6.5IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be rea...
CVE-2025-64186MEDIUM6.5Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verific...
CVE-2025-36223MEDIUM6.1IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST hea...
CVE-2025-8421MEDIUM6.6An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during i...
CVE-2025-64117MEDIUM4.6Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Editio...
CVE-2025-27368MEDIUM4.3IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected...
CVE-2025-13058MEDIUM5.4A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of t...
CVE-2025-12047MEDIUM6A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under ce...
CVE-2025-63927MEDIUM4A heap-use-after-free vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). During multi-threaded ...
CVE-2025-60646MEDIUM6.1A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitr...
CVE-2025-60645MEDIUM6.5A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module...
CVE-2025-25236MEDIUM5.3Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to en...
CVE-2025-20378MEDIUM6.1In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9...
CVE-2025-63419MEDIUM6.1Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now