2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9978MEDIUM6.8The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.ph...
CVE-2025-9158MEDIUM5.3The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which d...
CVE-2025-61931MEDIUM5.4Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attac...
CVE-2025-58070MEDIUM6.1Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to ...
CVE-2025-10874MEDIUM5.5The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2...
CVE-2025-7730MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter i...
CVE-2025-60023MEDIUM6.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit...
CVE-2025-59776MEDIUM6.3A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit...
CVE-2025-62517MEDIUM5.9Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1...
CVE-2025-62236MEDIUM6.9The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with ...
CVE-2025-57848MEDIUM6.4A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from...
CVE-2025-54966MEDIUM4.3An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return s...
CVE-2025-54963MEDIUM6.5An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi...
CVE-2025-62255MEDIUM6.1Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7....
CVE-2025-60859MEDIUM6.1Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via...
CVE-2025-60837MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in ...
CVE-2025-23345MEDIUM4.4NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause a...
CVE-2025-23332MEDIUM5NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger ...
CVE-2025-23330MEDIUM5.5NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer deref...
CVE-2025-23300MEDIUM5.5NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer d...
CVE-2025-10937MEDIUM6.8Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local ...
CVE-2025-61464MEDIUM6.5gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.ph...
CVE-2025-61413MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers ...
CVE-2025-57240MEDIUM6.1Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute ar...
CVE-2025-34156MEDIUM6.9Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now