2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-45806MEDIUM6.1A cross-site scripting (XSS) vulnerability in rrweb-snapshot before v2.0.0-alpha.18 allows attackers to execute arbitrar...
CVE-2025-9484MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.1...
CVE-2025-30650MEDIUM6.7A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a...
CVE-2025-57175MEDIUM6.8Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.
CVE-2025-14243MEDIUM5.3A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enum...
CVE-2025-58713MEDIUM6.4A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f...
CVE-2025-57854MEDIUM6.4A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from...
CVE-2025-57853MEDIUM6.4A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi...
CVE-2025-57851MEDIUM6.7A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f...
CVE-2025-57847MEDIUM6.4A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th...
CVE-2025-1794MEDIUM5.4The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all vers...
CVE-2025-14732MEDIUM6.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-20628MEDIUM6.9An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) w...
CVE-2025-14858MEDIUM5.1The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability...
CVE-2025-14857MEDIUM5.4An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware ...
CVE-2025-70844MEDIUM6.1yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Acco...
CVE-2025-14944MEDIUM5.3The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2...
CVE-2025-24819MEDIUM5.7Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter...
CVE-2025-15611MEDIUM5.4The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function be...
CVE-2025-65116MEDIUM5.5Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operati...
CVE-2025-13044MEDIUM6.2IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite ar...
CVE-2025-48651MEDIUM5.5In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to impr...
CVE-2025-61166MEDIUM6.1An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted ...
CVE-2025-47374MEDIUM6.5Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
CVE-2025-14938MEDIUM5.3The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now