2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36592MEDIUM5.4Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutra...
CVE-2025-12517MEDIUM5.3Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1....
CVE-2025-11998MEDIUM6.8The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing ...
CVE-2025-5347MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the r...
CVE-2025-5343MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the ...
CVE-2025-5342MEDIUM6.5Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.
CVE-2025-50574MEDIUM6.1Cross-site scripting (XSS) vulnerability in blog-details.php in Hiruna Gallage's Glamour Salon Management System v1 allo...
CVE-2025-50736MEDIUM6.1An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause t...
CVE-2025-63608MEDIUM5.4A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is loc...
CVE-2025-10348MEDIUM5.1URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account...
CVE-2025-10317MEDIUM5.1Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft s...
CVE-2025-62503MEDIUM4.6User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create...
CVE-2025-62402MEDIUM5.4API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server w...
CVE-2025-54941MEDIUM4.6An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a...
CVE-2025-54471MEDIUM6.5NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was repla...
CVE-2025-40090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list acc...
CVE-2025-11906MEDIUM6.7A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect...
CVE-2025-11881MEDIUM5.3The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
CVE-2025-11627MEDIUM6.5The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log ...
CVE-2025-10008MEDIUM5.3The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due...
CVE-2025-12475MEDIUM6.4The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsle...
CVE-2025-62257MEDIUM5.3Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Lifera...
CVE-2025-12083MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme ...
CVE-2025-10930MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects ...
CVE-2025-10929MEDIUM5.3Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Co...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now