2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-35031MEDIUM5.5Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker...
CVE-2025-57879MEDIUM6.1There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthe...
CVE-2025-57878MEDIUM6.1There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthe...
CVE-2025-57877MEDIUM4.8There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote...
CVE-2025-57876MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote,...
CVE-2025-57875MEDIUM4.8There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote...
CVE-2025-57874MEDIUM4.8There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote...
CVE-2025-57873MEDIUM4.8There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote...
CVE-2025-57872MEDIUM6.1There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthe...
CVE-2025-57871MEDIUM4.8There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote...
CVE-2025-36099MEDIUM4.9IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted...
CVE-2025-57197MEDIUM6In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for ...
CVE-2025-56807MEDIUM6.1A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrat...
CVE-2025-43400MEDIUM6.3An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 1...
CVE-2025-61659MEDIUM6.8bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
CVE-2025-41245MEDIUM4.9VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privi...
CVE-2025-11155MEDIUM6.8The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is n...
CVE-2025-36352MEDIUM5.4IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an ...
CVE-2025-36351MEDIUM4.3IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST A...
CVE-2025-57428MEDIUM6.5Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain...
CVE-2025-11147MEDIUM5.4Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be exe...
CVE-2025-11146MEDIUM5.4Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious ...
CVE-2025-10346MEDIUM6.1HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validatio...
CVE-2025-10345MEDIUM6.1HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validatio...
CVE-2025-10344MEDIUM6.1HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validatio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now