2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-56313MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3...
CVE-2025-63885MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to execute arbitrary web sc...
CVE-2025-60950MEDIUM6.1An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to ex...
CVE-2025-60319MEDIUM6.5PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttac...
CVE-2025-46363MEDIUM4.3Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative P...
CVE-2025-36592MEDIUM5.4Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutra...
CVE-2025-12517MEDIUM5.3Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1....
CVE-2025-11998MEDIUM6.8The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing ...
CVE-2025-5347MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the r...
CVE-2025-5343MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the ...
CVE-2025-5342MEDIUM6.5Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.
CVE-2025-50574MEDIUM6.1Cross-site scripting (XSS) vulnerability in blog-details.php in Hiruna Gallage's Glamour Salon Management System v1 allo...
CVE-2025-50736MEDIUM6.1An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause t...
CVE-2025-63608MEDIUM5.4A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is loc...
CVE-2025-10348MEDIUM5.1URVE Smart Office is vulnerable to Stored XSS in report problem functionality. An attacker with a low-privileged account...
CVE-2025-10317MEDIUM5.1Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft s...
CVE-2025-62503MEDIUM4.6User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create...
CVE-2025-62402MEDIUM5.4API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server w...
CVE-2025-54941MEDIUM4.6An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a...
CVE-2025-54471MEDIUM6.5NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was repla...
CVE-2025-40090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list acc...
CVE-2025-11906MEDIUM6.7A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect...
CVE-2025-11881MEDIUM5.3The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
CVE-2025-11627MEDIUM6.5The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log ...
CVE-2025-10008MEDIUM5.3The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now