2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10683MEDIUM4.9The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions ...
CVE-2025-64114MEDIUM6.5ClipBucket v5 is an open source video sharing platform. Versions 5.5.2 - #151 and below allow authenticated administrato...
CVE-2025-63585MEDIUM6.5OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp para...
CVE-2025-60784MEDIUM6.5A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou paramet...
CVE-2025-10853MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to i...
CVE-2025-63418MEDIUM6.1A DOM-based Cross-Site Scripting (XSS) vulnerability in the SelfBest platform 2023.3 allows attackers to execute arbitra...
CVE-2025-5770MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products du...
CVE-2025-56232MEDIUM6.8GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or ...
CVE-2025-55342MEDIUM5.3Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all...
CVE-2025-55341MEDIUM6.5Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad.
CVE-2025-43418MEDIUM4.6This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS...
CVE-2025-31954MEDIUM4.3HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to pro...
CVE-2025-59716MEDIUM5.3ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endp...
CVE-2025-57244MEDIUM5.4OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interfac...
CVE-2025-46424MEDIUM4.4Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerabilit...
CVE-2025-46366MEDIUM6.7Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel p...
CVE-2025-46365MEDIUM6.7Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticat...
CVE-2025-20377MEDIUM4.3A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker ...
CVE-2025-20374MEDIUM4.9A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory ...
CVE-2025-20305MEDIUM4.9A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obta...
CVE-2025-20304MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat...
CVE-2025-20303MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat...
CVE-2025-20289MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat...
CVE-2025-60753MEDIUM5.5An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c whe...
CVE-2025-52602MEDIUM4.2HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application.  An HTTP GET endpoint...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now