2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10131MEDIUM6.4The All Social Share Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sc' sho...
CVE-2025-10130MEDIUM6.4The Layers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all ...
CVE-2025-10128MEDIUM6.4The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aaq' ...
CVE-2025-10000MEDIUM6.4The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missin...
CVE-2025-61586MEDIUM5.3FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by s...
CVE-2025-59950MEDIUM5.4FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking p...
CVE-2025-59948MEDIUM5.4FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not sanitize certain event handler attrib...
CVE-2025-59941MEDIUM6.5go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.8 and below, go-f3's justification ...
CVE-2025-59940MEDIUM6.5mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerabil...
CVE-2025-43817MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay ...
CVE-2025-43812MEDIUM5.4Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Lifera...
CVE-2025-57769MEDIUM6.1FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below contain a vulnerability where a specially cr...
CVE-2025-43820MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the Calendar widget when inviting users to a event in Liferay Por...
CVE-2025-43818MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Calendar widget in Liferay Portal 7.4.3.35 through 7.4.3.110, and Lifera...
CVE-2025-43815MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability on the page configuration page in Liferay Portal 7.4.3.102 through 7....
CVE-2025-43811MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerability in the related asset selector in Liferay Portal 7.4.3.50 throug...
CVE-2025-34233MEDIUM6.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34232MEDIUM5.3Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34230MEDIUM5.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34229MEDIUM5.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34220MEDIUM5.3Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2...
CVE-2025-34211MEDIUM4.9Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version ...
CVE-2025-56764MEDIUM5.3Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning ...
CVE-2025-35034MEDIUM6.1Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_use...
CVE-2025-35033MEDIUM4.3Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now