2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54760MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaS...
CVE-2025-52583MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a...
CVE-2025-24833MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary...
CVE-2025-58115MEDIUM6.1ChatLuck contains a cross-site scripting vulnerability in Guest User Sign-up. If exploited, an arbitrary script may be e...
CVE-2025-54461MEDIUM6.9ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited...
CVE-2025-53858MEDIUM5.4ChatLuck contains a cross-site scripting vulnerability in Chat Rooms. If exploited, an arbitrary script may be executed ...
CVE-2025-41410MEDIUM5.4Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Sl...
CVE-2025-10545MEDIUM4.3Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding c...
CVE-2025-0277MEDIUM6.1HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP)...
CVE-2025-0276MEDIUM6.1HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Conte...
CVE-2025-55091MEDIUM6.5In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...
CVE-2025-41443MEDIUM4.3Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessin...
CVE-2025-41021MEDIUM5.4Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validati...
CVE-2025-55090MEDIUM6.5In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...
CVE-2025-55084MEDIUM5.3In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_...
CVE-2025-10849MEDIUM5.3The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2025-0275MEDIUM4.3HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset ...
CVE-2025-11814MEDIUM6.4The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to...
CVE-2025-0274MEDIUM4.3HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users ca...
CVE-2025-10700MEDIUM4.3The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-11683MEDIUM6.5YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential info...
CVE-2025-62375MEDIUM6.9go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness ...
CVE-2025-43313MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, ...
CVE-2025-43282MEDIUM5.5A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPad...
CVE-2025-43280MEDIUM4.7The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an emai...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now