2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-57521MEDIUM6.1Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application...
CVE-2025-56450MEDIUM6.5Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter ...
CVE-2025-6239MEDIUM6.5Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Di...
CVE-2025-7473MEDIUM5.3Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
CVE-2025-10612MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Info...
CVE-2025-26392MEDIUM4.6SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using...
CVE-2025-62702MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62701MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62694MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62699MEDIUM6.9Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Transla...
CVE-2025-62696MEDIUM6.9Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Found...
CVE-2025-62695MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-54764MEDIUM6.2Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i...
CVE-2025-12001MEDIUM6.1Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B...
CVE-2025-11536MEDIUM5The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver...
CVE-2025-62657MEDIUM5.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62656MEDIUM5.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-60783MEDIUM6.5There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerabilit...
CVE-2025-60781MEDIUM6.1PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_nam...
CVE-2025-8051MEDIUM6.5Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal.  The vulnerability could allow a user ...
CVE-2025-8048MEDIUM6.5External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could a...
CVE-2025-62528MEDIUM5.4Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ...
CVE-2025-62522MEDIUM6Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5...
CVE-2025-5517MEDIUM6.8Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC ...
CVE-2025-62700MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now