2025 CVE Vulnerabilities

45,327 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-42706MEDIUM6.5A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute co...
CVE-2025-42701MEDIUM5.6A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute...
CVE-2025-11485MEDIUM4.8A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user...
CVE-2025-60318MEDIUM6.1SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi...
CVE-2025-59303MEDIUM6.4HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snipp...
CVE-2025-36636MEDIUM4.3In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticat...
CVE-2025-61672MEDIUM5.3Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3...
CVE-2025-60834MEDIUM6.5A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying...
CVE-2025-60313MEDIUM6.1Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input fi...
CVE-2025-43771MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4....
CVE-2025-43724MEDIUM4.4Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerab...
CVE-2025-61183MEDIUM6.1Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the stor...
CVE-2025-60833MEDIUM6.5An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to e...
CVE-2025-60830MEDIUM6.5redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.
CVE-2025-60828MEDIUM6.5WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine in...
CVE-2025-60314MEDIUM5.4Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input...
CVE-2025-43830MEDIUM6.1Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023...
CVE-2025-43829MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through ...
CVE-2025-60299MEDIUM5.4Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addComme...
CVE-2025-60298MEDIUM5.4Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updat...
CVE-2025-43821MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through...
CVE-2025-10649MEDIUM6.5The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and inc...
CVE-2025-11445MEDIUM6.3A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webv...
CVE-2025-11443MEDIUM5.9A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/passwor...
CVE-2025-11442MEDIUM4.3A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3. The impacted element is an unknown function of the c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now