2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59843MEDIUM5.3Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[use...
CVE-2025-59842MEDIUM4.3jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit...
CVE-2025-59362MEDIUM4Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.
CVE-2025-56463MEDIUM6.8Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.
CVE-2025-11027MEDIUM5.4A vulnerability was identified in givanz Vvveb up to 1.0.7.2. Affected by this issue is some unknown functionality of th...
CVE-2025-6396MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webbeyaz We...
CVE-2025-57292MEDIUM6.1Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The applica...
CVE-2025-11019MEDIUM4.8A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Men...
CVE-2025-11017MEDIUM5.5A vulnerability was detected in OGRECave Ogre up to 14.4.1. The impacted element is the function Ogre::LogManager::strea...
CVE-2025-11016MEDIUM4.3A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileO...
CVE-2025-11015MEDIUM5.3A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the fil...
CVE-2025-11060MEDIUM5.7A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or gu...
CVE-2025-11025MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. V...
CVE-2025-11013MEDIUM5.5A vulnerability was identified in BehaviorTree up to 4.7.0. This vulnerability affects the function XMLParser::PImpl::lo...
CVE-2025-11011MEDIUM5.5A vulnerability was found in BehaviorTree up to 4.7.0. Affected by this issue is the function JsonExporter::fromJson of ...
CVE-2025-11010MEDIUM5.3A vulnerability has been found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_includ...
CVE-2025-5069MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18...
CVE-2025-10868MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18....
CVE-2025-60186MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Moss Google+ ...
CVE-2025-60185MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kontur.us kontur A...
CVE-2025-60184MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. SEO Searc...
CVE-2025-60181MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Server Sid...
CVE-2025-60179MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Space Studio Click...
CVE-2025-60177MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rozx Recaptcha – w...
CVE-2025-60167MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in honzat Page Manager for Elem...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now