2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62245MEDIUM4.3Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 thr...
CVE-2025-62158MEDIUM5.3Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system d...
CVE-2025-61925MEDIUM6.5Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `...
CVE-2025-61505MEDIUM6.5e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-co...
CVE-2025-60838MEDIUM6.5An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted...
CVE-2025-60268MEDIUM6.5An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the sa...
CVE-2025-11618MEDIUM5.3A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer derefer...
CVE-2025-11617MEDIUM5.4A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when rec...
CVE-2025-11616MEDIUM5.4A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when r...
CVE-2025-11580MEDIUM5.5A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This mani...
CVE-2025-61780MEDIUM5.3Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclos...
CVE-2025-60308MEDIUM4.1code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room ...
CVE-2025-8887MEDIUM6.1Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unautho...
CVE-2025-8886MEDIUM6.7Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missi...
CVE-2025-61319MEDIUM6.1ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. Whe...
CVE-2025-61152MEDIUM6.5python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature ...
CVE-2025-60868MEDIUM6.5The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Str...
CVE-2025-62239MEDIUM5.4Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and L...
CVE-2025-62238MEDIUM5.4Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 th...
CVE-2025-62237MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.11...
CVE-2025-7781MEDIUM6.4The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘...
CVE-2025-7374MEDIUM5.4The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions ...
CVE-2025-11579MEDIUM6.5github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary siz...
CVE-2025-52624MEDIUM6.1A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-...
CVE-2025-11190MEDIUM5.4The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redire...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now