2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10937MEDIUM6.8Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local ...
CVE-2025-61464MEDIUM6.5gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.ph...
CVE-2025-61413MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers ...
CVE-2025-57240MEDIUM6.1Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute ar...
CVE-2025-34156MEDIUM6.9Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /c...
CVE-2025-34155MEDIUM6.9Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authen...
CVE-2025-50951MEDIUM6.5FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.
CVE-2025-50949MEDIUM6.5FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.
CVE-2025-12114MEDIUM5.5Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue af...
CVE-2025-56009MEDIUM5.3Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take...
CVE-2025-56008MEDIUM6.1Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near t...
CVE-2025-56007MEDIUM6.5CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding addi...
CVE-2025-12110MEDIUM5.4A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the...
CVE-2025-62256MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA...
CVE-2025-60852MEDIUM6.5A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built wi...
CVE-2025-53702MEDIUM6.5Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same l...
CVE-2025-53701MEDIUM6.1Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET re...
CVE-2025-1679MEDIUM4.8Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attac...
CVE-2025-11429MEDIUM5.4A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on ...
CVE-2025-8427MEDIUM5.4The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a...
CVE-2025-11128MEDIUM5The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2025-10705MEDIUM5.3The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver...
CVE-2025-62401MEDIUM4.3An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them m...
CVE-2025-62400MEDIUM6.5Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden g...
CVE-2025-62398MEDIUM5.4A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now