2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62667MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62666MEDIUM6.9Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch ...
CVE-2025-62664MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62663MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62662MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-11361MEDIUM6.4The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Serv...
CVE-2025-62665MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-11378MEDIUM5.4The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized...
CVE-2025-62652MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2025-62651MEDIUM5.8The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for th...
CVE-2025-62649MEDIUM5.8The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for...
CVE-2025-62648MEDIUM5.8The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive ...
CVE-2025-62647MEDIUM5.8The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning ...
CVE-2025-62508MEDIUM6.5Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulne...
CVE-2025-62511MEDIUM6.3yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 ...
CVE-2025-11925MEDIUM6.1Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially all...
CVE-2025-11913MEDIUM6.5A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is ...
CVE-2025-56320MEDIUM5.4CobbleStone Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its cha...
CVE-2025-34281MEDIUM5.4ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Galle...
CVE-2025-62430MEDIUM5.4ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site ...
CVE-2025-62424MEDIUM6.5ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/templa...
CVE-2025-62421MEDIUM5.4DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scrip...
CVE-2025-60514MEDIUM6.5Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts.
CVE-2025-57164MEDIUM6.5Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase ...
CVE-2025-58747MEDIUM6.1Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now