2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6016MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and ...
CVE-2025-3922MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2025-0186MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2025-58922MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affect...
CVE-2025-41011MEDIUM6.1HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the vic...
CVE-2025-31981MEDIUM5.3HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, al...
CVE-2025-1241MEDIUM4.9Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize...
CVE-2025-10354MEDIUM5.1Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execu...
CVE-2025-66954MEDIUM6.5A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to...
CVE-2025-66335MEDIUM5.3Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context han...
CVE-2025-13480MEDIUM6.5Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only re...
CVE-2025-70795MEDIUM5.5STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCT...
CVE-2025-46641MEDIUM6.6Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont...
CVE-2025-15622MEDIUM6.2Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals ...
CVE-2025-54510MEDIUM5.9A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with admi...
CVE-2025-43937MEDIUM6.6Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerab...
CVE-2025-43935MEDIUM4.4Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A hi...
CVE-2025-43883MEDIUM4.1Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vuln...
CVE-2025-36579MEDIUM5.1Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with ph...
CVE-2025-15621MEDIUM6Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the re...
CVE-2025-12624MEDIUM5.4Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This fail...
CVE-2025-6024MEDIUM6.1The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script...
CVE-2025-13364MEDIUM6.4The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera...
CVE-2025-15636MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design You...
CVE-2025-15635MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now