2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-34308MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34307MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34306MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34305MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain multiple stored cross-site scripting (XSS) vulnerabilities cause...
CVE-2025-34304MEDIUM6.5IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attac...
CVE-2025-34303MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34302MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-34301MEDIUM5.4IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an...
CVE-2025-12390MEDIUM6A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use...
CVE-2025-12103MEDIUM5A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a...
CVE-2025-40040MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/ksm: fix flag-dropping behavior in ksm_madvise ...
CVE-2025-40039MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access...
CVE-2025-55758MEDIUM5.4Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.
CVE-2025-12344MEDIUM6.3A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /...
CVE-2025-33133MEDIUM6.5IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authen...
CVE-2025-33132MEDIUM6.5IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authen...
CVE-2025-33131MEDIUM6.5IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authen...
CVE-2025-33126MEDIUM6.5IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0....
CVE-2025-12335MEDIUM6.1A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown fun...
CVE-2025-12332MEDIUM4.8A flaw has been found in SourceCodester Student Grades Management System 1.0. This affects the function delete_user of t...
CVE-2025-62259MEDIUM5.4Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4...
CVE-2025-62258MEDIUM6.5CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3....
CVE-2025-12334MEDIUM6.1A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/pr...
CVE-2025-12333MEDIUM6.1A vulnerability has been found in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pa...
CVE-2025-62793MEDIUM6.8eLabFTW is an open source electronic lab notebook for research labs. The application served uploaded SVG files inline. B...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now