2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62595MEDIUM6.1Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to ...
CVE-2025-60511MEDIUM4.3Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability...
CVE-2025-60506MEDIUM5.4Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An ...
CVE-2025-62250MEDIUM6.5Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023....
CVE-2025-61194MEDIUM6.5daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.
CVE-2025-61181MEDIUM6.5daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.
CVE-2025-60280MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code ...
CVE-2025-60934MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Perfor...
CVE-2025-60933MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Perf...
CVE-2025-60932MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Per...
CVE-2025-59438MEDIUM5.3Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.
CVE-2025-57521MEDIUM6.1Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application...
CVE-2025-56450MEDIUM6.5Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter ...
CVE-2025-6239MEDIUM6.5Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Di...
CVE-2025-7473MEDIUM5.3Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
CVE-2025-10612MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Info...
CVE-2025-26392MEDIUM4.6SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using...
CVE-2025-62702MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62701MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62694MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62699MEDIUM6.9Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Transla...
CVE-2025-62696MEDIUM6.9Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Found...
CVE-2025-62695MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-54764MEDIUM6.2Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_i...
CVE-2025-12001MEDIUM6.1Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; B...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now