2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15064MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-13368MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the P...
CVE-2025-68153MEDIUM6.5Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ...
CVE-2025-68152MEDIUM4.9Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ...
CVE-2025-59709MEDIUM6.8An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read b...
CVE-2025-43238MEDIUM6.2An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonom...
CVE-2025-43210MEDIUM6.3An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18...
CVE-2025-66487MEDIUM6.5IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send em...
CVE-2025-66486MEDIUM6.1IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2025-66485MEDIUM5.4IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by...
CVE-2025-66484MEDIUM5.4IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to ...
CVE-2025-66483MEDIUM6.5IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authentic...
CVE-2025-36373MEDIUM6.8IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I...
CVE-2025-66442MEDIUM5.1In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occ...
CVE-2025-67807MEDIUM4.7The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumer...
CVE-2025-67806MEDIUM5.3The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumer...
CVE-2025-13535MEDIUM6.4The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Sc...
CVE-2025-71280MEDIUM5.5XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu...
CVE-2025-41357MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to...
CVE-2025-41356MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to...
CVE-2025-41355MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker t...
CVE-2025-10553MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manag...
CVE-2025-10551MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovat...
CVE-2025-66215MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to t...
CVE-2025-66038MEDIUM6.8OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a com...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now