2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10355MEDIUM5.1Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious UR...
CVE-2025-41073MEDIUM6.5Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated atta...
CVE-2025-40643MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du...
CVE-2025-9981MEDIUM4.8QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with adm...
CVE-2025-9980MEDIUM4.8QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin p...
CVE-2025-10727MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner S...
CVE-2025-62499MEDIUM4.8Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted in...
CVE-2025-54856MEDIUM4.8Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored b...
CVE-2025-54806MEDIUM6.1GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a...
CVE-2025-62820MEDIUM4.9Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within t...
CVE-2025-48430MEDIUM5.5Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Comm...
CVE-2025-48428MEDIUM6.7Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated us...
CVE-2025-41402MEDIUM5.5Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to e...
CVE-2025-35981MEDIUM5.5Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privil...
CVE-2025-62710MEDIUM5.9Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initial...
CVE-2025-62706MEDIUM6.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF...
CVE-2025-62705MEDIUM4.9OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not ...
CVE-2025-62613MEDIUM6.9VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to b...
CVE-2025-62612MEDIUM5.3FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link i...
CVE-2025-62247MEDIUM6.5Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 20...
CVE-2025-62248MEDIUM4.8A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Porta...
CVE-2025-58712MEDIUM6.4A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file...
CVE-2025-24934MEDIUM5.4Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. ...
CVE-2025-22178MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22177MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now