2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-43911MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-43906MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-43890MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-1826MEDIUM5.4IBM Engineering Requirements Management DOORS Next (IBM Jazz Foundation 7.0.2 to 7.0.2 iFix034, 7.0.3 to 7.0.3 iFix016, ...
CVE-2025-56243MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability was found in the register.php page of PuneethReddyHC Event Management System ...
CVE-2025-60312MEDIUM6.1Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" fie...
CVE-2025-53476MEDIUM5.3A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5c...
CVE-2025-37728MEDIUM5.4Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A ma...
CVE-2025-25009MEDIUM5.4Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
CVE-2025-40888MEDIUM6.5A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. ...
CVE-2025-40887MEDIUM6.5A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter...
CVE-2025-40885MEDIUM6.5A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input p...
CVE-2025-40676MEDIUM5.3Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Rese...
CVE-2025-40649MEDIUM5.1Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infras...
CVE-2025-3718MEDIUM5.4A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing valid...
CVE-2025-11390MEDIUM6.1A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-11360MEDIUM5.3A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the ...
CVE-2025-10645MEDIUM5.3The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ...
CVE-2025-7400MEDIUM6.4The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featur...
CVE-2025-61768MEDIUM5.1KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Fo...
CVE-2025-43824MEDIUM5.4The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 ...
CVE-2025-59452MEDIUM5.8The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an...
CVE-2025-59450MEDIUM4.3The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network a...
CVE-2025-59449MEDIUM4.9The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-ac...
CVE-2025-59448MEDIUM4.7Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now