2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61926MEDIUM4.6Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Rev...
CVE-2025-62240MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, a...
CVE-2025-61783MEDIUM6.3Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, t...
CVE-2025-43296MEDIUM5.5A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeepe...
CVE-2025-35061MEDIUM5.9Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker t...
CVE-2025-35060MEDIUM5.4Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to u...
CVE-2025-35059MEDIUM6.1Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl...
CVE-2025-35058MEDIUM5.9Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NI...
CVE-2025-35057MEDIUM6Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NI...
CVE-2025-35056MEDIUM5Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and...
CVE-2025-35054MEDIUM5.3Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>...
CVE-2025-35053MEDIUM6.4Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedP...
CVE-2025-35052MEDIUM6.3Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values ...
CVE-2025-55200MEDIUM5.4BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a St...
CVE-2025-60267MEDIUM6.5In xckk v9.6, there is a SQL injection vulnerability in which the cond parameter in notice/list is not securely filtered...
CVE-2025-11550MEDIUM6.5A vulnerability was found in Tenda W12 3.0.0.6(3948). The impacted element is the function wifiScheduledSet of the file ...
CVE-2025-60304MEDIUM6.1code-projects Simple Scheduling System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Subject Description field...
CVE-2025-60266MEDIUM6.5In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in address/list is not securely filt...
CVE-2025-60010MEDIUM5.4A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenti...
CVE-2025-60009MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-60006MEDIUM5.3Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vu...
CVE-2025-60002MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-60001MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-60000MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-59999MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now