2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58152MEDIUM6.9FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection i...
CVE-2025-11191MEDIUM5.3The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the cr...
CVE-2025-11975MEDIUM4.3The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)...
CVE-2025-11806MEDIUM6.4The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all ver...
CVE-2025-48980MEDIUM6.5In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split Vie...
CVE-2025-27208MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker c...
CVE-2025-34283MEDIUM6.5Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Nept...
CVE-2025-34278MEDIUM5.4Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source...
CVE-2025-34273MEDIUM6.5Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administ...
CVE-2025-34272MEDIUM6.5In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the applicatio...
CVE-2025-34270MEDIUM4.9Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fa...
CVE-2025-34135MEDIUM4.4Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. ...
CVE-2025-62265MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupp...
CVE-2025-57109MEDIUM6.5Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When pr...
CVE-2025-52180MEDIUM6.1Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated atta...
CVE-2025-52179MEDIUM6.1Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated at...
CVE-2025-64118MEDIUM6.1node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uni...
CVE-2025-64116MEDIUM6.1Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts...
CVE-2025-64115MEDIUM6.1Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use...
CVE-2025-62266MEDIUM6.1By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 20...
CVE-2025-56313MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3...
CVE-2025-63885MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to execute arbitrary web sc...
CVE-2025-60950MEDIUM6.1An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to ex...
CVE-2025-60319MEDIUM6.5PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttac...
CVE-2025-46363MEDIUM4.3Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative P...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now