2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58084MEDIUM6.5Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing ...
CVE-2025-62243MEDIUM5.4Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Lif...
CVE-2025-61775MEDIUM6.9Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unex...
CVE-2025-62244MEDIUM4.3Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Lif...
CVE-2025-39965MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id....
CVE-2025-39964MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_a...
CVE-2025-9337MEDIUM6.8A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a speciall...
CVE-2025-9336MEDIUM6.8A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipu...
CVE-2025-11184MEDIUM6.9Cross-site scripting vulnerability in QGIS QWC2 Registration GUI <=v2025.03.31 allows an authorized attacker to plant ar...
CVE-2025-11183MEDIUM6.9Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 <2025.08.14 allows an authorized attacker to plant ar...
CVE-2025-10720MEDIUM6.5The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However...
CVE-2025-11674MEDIUM6.9SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to...
CVE-2025-11672MEDIUM6.9Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthentic...
CVE-2025-11671MEDIUM6.9Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthentic...
CVE-2025-10558MEDIUM6.1A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows a...
CVE-2025-10557MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator ...
CVE-2025-10556MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager fro...
CVE-2025-10552MEDIUM6.1A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an ...
CVE-2025-27259MEDIUM5.4Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limite...
CVE-2025-9698MEDIUM6.8The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow use...
CVE-2025-11663MEDIUM6.1A weakness has been identified in Campcodes Online Beauty Parlor Management System 1.0. The affected element is an unkno...
CVE-2025-31994MEDIUM4.3HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious scr...
CVE-2025-11655MEDIUM4.7A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted elemen...
CVE-2025-11650MEDIUM4A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the f...
CVE-2025-11649MEDIUM6.3A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the compon...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now