2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62267MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7....
CVE-2025-12546MEDIUM5.4A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen...
CVE-2025-62264MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, an...
CVE-2025-6075MEDIUM5.5If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env...
CVE-2025-59501MEDIUM4.8Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing o...
CVE-2025-12357MEDIUM6.3By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker ca...
CVE-2025-64387MEDIUM5.1The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is i...
CVE-2025-61427MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execu...
CVE-2025-12521MEDIUM5.3The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-12460MEDIUM5.3An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially craft...
CVE-2025-4952MEDIUM6.8Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the...
CVE-2025-36249MEDIUM5.3IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or se...
CVE-2025-64368MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issu...
CVE-2025-64367MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groun...
CVE-2025-64365MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extr...
CVE-2025-64362MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen K Ele...
CVE-2025-64361MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Con...
CVE-2025-64358MEDIUM4.3Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows E...
CVE-2025-64357MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allow...
CVE-2025-64356MEDIUM4.3Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorre...
CVE-2025-64354MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gut...
CVE-2025-64351MEDIUM4.3Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows R...
CVE-2025-40603MEDIUM4.5A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, aut...
CVE-2025-11602MEDIUM6.3Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obta...
CVE-2025-12041MEDIUM5.3The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now