2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36172MEDIUM5.4IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0...
CVE-2025-11193MEDIUM6.8A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application...
CVE-2025-63293MEDIUM6.5FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user ...
CVE-2025-12657MEDIUM5.5The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them i...
CVE-2025-63593MEDIUM6.1Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).
CVE-2025-8558MEDIUM5.4Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allo...
CVE-2025-50363MEDIUM5.4Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name...
CVE-2025-10280MEDIUM6.1IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels includin...
CVE-2025-63450MEDIUM5.4Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.
CVE-2025-63449MEDIUM5.4Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.
CVE-2025-63448MEDIUM6.1Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.
CVE-2025-63447MEDIUM6.1Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.
CVE-2025-63446MEDIUM6.1Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.
CVE-2025-36092MEDIUM6.5IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of ...
CVE-2025-36091MEDIUM4.3IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards t...
CVE-2025-63443MEDIUM5.4School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.
CVE-2025-63442MEDIUM4.6Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. T...
CVE-2025-60892MEDIUM6.8An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-...
CVE-2025-45663MEDIUM6.5An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
CVE-2025-29699MEDIUM6.5NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.
CVE-2025-64294MEDIUM5.3Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Co...
CVE-2025-12626MEDIUM4.3A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects...
CVE-2025-12616MEDIUM5.9A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onp...
CVE-2025-6988MEDIUM6.4The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a...
CVE-2025-12137MEDIUM4.9The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Re...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now