2025 CVE Vulnerabilities

45,328 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11442MEDIUM4.3A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3. The impacted element is an unknown function of the c...
CVE-2025-48464MEDIUM4.7Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync a...
CVE-2025-11440MEDIUM4.3A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Execut...
CVE-2025-11439MEDIUM4.3A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/i...
CVE-2025-11438MEDIUM6.3A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /cust...
CVE-2025-11437MEDIUM4.8A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the c...
CVE-2025-11435MEDIUM6.1A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown ...
CVE-2025-11171MEDIUM5.3The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all...
CVE-2025-11433MEDIUM6.1A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of t...
CVE-2025-11425MEDIUM4.8A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Affected is an unknown function ...
CVE-2025-11421MEDIUM5.4A flaw has been found in code-projects Voting System 1.0. The affected element is an unknown function of the file /admin...
CVE-2025-61999MEDIUM4.8OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload JavaScript or other content embedded in an SV...
CVE-2025-61998MEDIUM4.8OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within t...
CVE-2025-61997MEDIUM4.8OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual...
CVE-2025-61996MEDIUM4.8OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual...
CVE-2025-43822MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP...
CVE-2025-11414MEDIUM5.5A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry ...
CVE-2025-43823MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111,...
CVE-2025-11413MEDIUM5.5A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elf...
CVE-2025-11412MEDIUM5.5A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd...
CVE-2025-44824MEDIUM6.5Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch ser...
CVE-2025-43910MEDIUM4.4Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-36569MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1....
CVE-2025-36567MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1....
CVE-2025-36566MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now