2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64296MEDIUM5.3Missing Authorization vulnerability in Facebook Facebook for WooCommerce facebook-for-woocommerce allows Exploiting Inco...
CVE-2025-57931MEDIUM5.3Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.Thi...
CVE-2025-64094MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1...
CVE-2025-62802MEDIUM4.3DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1...
CVE-2025-62800MEDIUM6.1FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0 have a reflected cross-site sc...
CVE-2025-62798MEDIUM5.4Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vu...
CVE-2025-62796MEDIUM5.8PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Versions 1.7.7 through 2.0.1 allow ...
CVE-2025-61598MEDIUM5.3Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response he...
CVE-2025-11375MEDIUM6.5Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum...
CVE-2025-11374MEDIUM6.5Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect C...
CVE-2025-62367MEDIUM4.8Taiga is an open source project management platform. In versions 6.8.3 and earlier, Taiga API is vulnerable to time-base...
CVE-2025-27093MEDIUM6.3Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in ...
CVE-2025-61080MEDIUM5.4A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Clear2Pay Bank Visibility Application - Paym...
CVE-2025-61155MEDIUM5.5The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in ...
CVE-2025-36085MEDIUM5.4IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenti...
CVE-2025-36083MEDIUM5.5IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to ...
CVE-2025-36081MEDIUM5.3IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log...
CVE-2025-34318MEDIUM5.1IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34317MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34316MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34315MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34314MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34313MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34310MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34309MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now