2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59988MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-59987MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-59986MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-59985MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-59984MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-59983MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-59982MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-59981MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-59980MEDIUM6.9An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, ...
CVE-2025-61532MEDIUM6.1Cross Site Scripting vulnerability in SVX Portal v.2.7A to execute arbitrary code via the TG parameter on last_heard_pag...
CVE-2025-60302MEDIUM6.1code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, t...
CVE-2025-60265MEDIUM6.5In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in user/list is not securely filtere...
CVE-2025-59962MEDIUM6An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and J...
CVE-2025-59958MEDIUM6.9An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper N...
CVE-2025-56426MEDIUM6.5An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, s...
CVE-2025-10282MEDIUM4.7BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious form...
CVE-2025-10281MEDIUM4.7BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious f...
CVE-2025-39664MEDIUM6.5Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows auth...
CVE-2025-32916MEDIUM4.3Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p4...
CVE-2025-36225MEDIUM4.3IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user d...
CVE-2025-36171MEDIUM4.9IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly vali...
CVE-2025-39961MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase p...
CVE-2025-9371MEDIUM6.4The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versi...
CVE-2025-2934MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, an...
CVE-2025-10249MEDIUM6.5The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missin...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now