2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67709MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67708MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67707MEDIUM5.6ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem...
CVE-2025-67706MEDIUM5.6ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem...
CVE-2025-67705MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67704MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-67703MEDIUM6.1There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some co...
CVE-2025-69288CRITICAL9.1Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user...
CVE-2025-69286CRITICAL9.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecu...
CVE-2025-68700HIGH8.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged aut...
CVE-2025-34469HIGH7.5Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implemen...
CVE-2025-15398HIGH8.1A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the ...
CVE-2025-53235HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Soc...
CVE-2025-66148MEDIUM5.4Missing Authorization vulnerability in merkulove Conformer for Elementor conformer-elementor allows Exploiting Incorrect...
CVE-2025-66146MEDIUM5.4Missing Authorization vulnerability in merkulove Logger for Elementor logger-elementor allows Exploiting Incorrectly Con...
CVE-2025-66145MEDIUM5.4Missing Authorization vulnerability in merkulove Worker for WPBakery worker-wpbakery allows Exploiting Incorrectly Confi...
CVE-2025-66144MEDIUM5.4Missing Authorization vulnerability in merkulove Worker for Elementor worker-elementor allows Exploiting Incorrectly Con...
CVE-2025-52739HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows ...
CVE-2025-50053HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta...
CVE-2025-47566HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows ...
CVE-2025-31054HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from...
CVE-2025-30628HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Aff...
CVE-2025-28973MEDIUM6.5Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path T...
CVE-2025-28949HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay...
CVE-2025-23757HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proloy Chakroborty...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now