2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61780MEDIUM5.3Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclos...
CVE-2025-60308MEDIUM4.1code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room ...
CVE-2025-8887MEDIUM6.1Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unautho...
CVE-2025-8886MEDIUM6.7Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missi...
CVE-2025-61319MEDIUM6.1ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. Whe...
CVE-2025-61152MEDIUM6.5python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature ...
CVE-2025-60868MEDIUM6.5The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Str...
CVE-2025-62239MEDIUM5.4Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and L...
CVE-2025-62238MEDIUM5.4Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 th...
CVE-2025-62237MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.11...
CVE-2025-7781MEDIUM6.4The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘...
CVE-2025-7374MEDIUM5.4The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions ...
CVE-2025-11579MEDIUM6.5github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary siz...
CVE-2025-52624MEDIUM6.1A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-...
CVE-2025-11190MEDIUM5.4The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redire...
CVE-2025-52650MEDIUM6.1Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
CVE-2025-41089MEDIUM4.8Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user in...
CVE-2025-41088MEDIUM5.1Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. T...
CVE-2025-37727MEDIUM5.7Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preco...
CVE-2025-25018MEDIUM5.4Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
CVE-2025-25017MEDIUM6.1Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
CVE-2025-40640MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du...
CVE-2025-62292MEDIUM4.3In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/...
CVE-2025-21070MEDIUM5.5Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-o...
CVE-2025-21065MEDIUM6.6Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now