2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62248MEDIUM4.8A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Porta...
CVE-2025-58712MEDIUM6.4A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file...
CVE-2025-24934MEDIUM5.4Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. ...
CVE-2025-22178MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22177MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22176MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22175MEDIUM5.4Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22174MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22173MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22172MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22171MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of othe...
CVE-2025-22170MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an act...
CVE-2025-22169MEDIUM5.4Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-22168MEDIUM4.3Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a...
CVE-2025-11958MEDIUM5.1An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier a...
CVE-2025-62607MEDIUM5.3Nautobot Single Source of Truth (SSoT) is an app for Nautobot. Prior to version 3.10.0, an unauthenticated attacker coul...
CVE-2025-23299MEDIUM6.7NVIDIA Bluefield and ConnectX contain a vulnerability in the management interface that could allow a malicious actor wit...
CVE-2025-62073MEDIUM4.3Missing Authorization vulnerability in Sovlix MeetingHub meetinghub.This issue affects MeetingHub: from n/a through <= 1...
CVE-2025-62072MEDIUM4.3Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users.This issue affects Front End User...
CVE-2025-62071MEDIUM4.3Missing Authorization vulnerability in Repuso Social proof testimonials and reviews by Repuso social-testimonials-and-re...
CVE-2025-62070MEDIUM4.3Missing Authorization vulnerability in WPXPO WowRevenue revenue.This issue affects WowRevenue: from n/a through <= 1.2.1...
CVE-2025-62069MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 MDTF wp...
CVE-2025-62068MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf e2pdf e2pdf....
CVE-2025-62063MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Trave...
CVE-2025-62062MEDIUM5.5Insertion of Sensitive Information Into Sent Data vulnerability in ThemeRuby Easy Post Submission easy-post-submission a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now