2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53533MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker bloc...
CVE-2025-46602MEDIUM5.5Dell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externall...
CVE-2025-36170MEDIUM5.4IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This v...
CVE-2025-36138MEDIUM5.4IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to stored cross-site scripting. This v...
CVE-2025-32785MEDIUM5.4Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker bloc...
CVE-2025-12365MEDIUM5.3Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12304MEDIUM4.3A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affe...
CVE-2025-61795MEDIUM5.3Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits)...
CVE-2025-60983MEDIUM5.4Reflected Cross Site Scripting vulnerability in Rubikon Banking Solution 4.0.3 in the "Search For Customers Information"...
CVE-2025-60982MEDIUM5.4IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object r...
CVE-2025-54965MEDIUM6.1An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize...
CVE-2025-12303MEDIUM4.8A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of ...
CVE-2025-12302MEDIUM6.1A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown functi...
CVE-2025-12300MEDIUM6.1A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown process...
CVE-2025-54970MEDIUM6.5An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests...
CVE-2025-54969MEDIUM6.1An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protec...
CVE-2025-54967MEDIUM6.5An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An att...
CVE-2025-12299MEDIUM6.1A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown...
CVE-2025-12298MEDIUM6.1A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the fil...
CVE-2025-12297MEDIUM4.3A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController....
CVE-2025-60791MEDIUM6.2Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application lea...
CVE-2025-12291MEDIUM4.7A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an u...
CVE-2025-10023MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-36121MEDIUM5.4IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML...
CVE-2025-12351MEDIUM6.8Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker cou...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now