2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-41356MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to...
CVE-2025-41355MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker t...
CVE-2025-10553MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manag...
CVE-2025-10551MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovat...
CVE-2025-66215MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t...
CVE-2025-66038MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com...
CVE-2025-66037MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_p...
CVE-2025-49010MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t...
CVE-2025-3716MEDIUM5.3User enumeration in ESET Protect (on-prem) via Response Timing.
CVE-2025-15445MEDIUM5.4The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability c...
CVE-2025-69988MEDIUM6.5BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proxi...
CVE-2025-61190MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover ...
CVE-2025-59031MEDIUM4.3Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachmen...
CVE-2025-55264MEDIUM5.5HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a s...
CVE-2025-55277MEDIUM6.5HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make us...
CVE-2025-55276MEDIUM5.3HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organiz...
CVE-2025-55274MEDIUM4.3HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the expo...
CVE-2025-55273MEDIUM4.3HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts ca...
CVE-2025-55272MEDIUM5.3HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s softw...
CVE-2025-55268MEDIUM5.3HCL Aftermarket DPC is affected by Spamming Vulnerability which can allow the actor to excessive spamming can consume se...
CVE-2025-55266MEDIUM6.5HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr...
CVE-2025-41027MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS...
CVE-2025-41026MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaS...
CVE-2025-15488MEDIUM6.5The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software al...
CVE-2025-15433MEDIUM6.8The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now