2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10499MEDIUM4.3The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2025-10498MEDIUM5.4The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2025-8440MEDIUM6.4The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in...
CVE-2025-36239MEDIUM6.1IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an u...
CVE-2025-59938MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from ...
CVE-2025-36144MEDIUM5.5IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local use...
CVE-2025-57692MEDIUM6.8PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, e...
CVE-2025-11034MEDIUM4.3A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element is the function download...
CVE-2025-26258MEDIUM6.1Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.'
CVE-2025-11031MEDIUM5.5A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/res...
CVE-2025-59843MEDIUM5.3Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[use...
CVE-2025-59842MEDIUM4.3jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit...
CVE-2025-59362MEDIUM4Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.
CVE-2025-56463MEDIUM6.8Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.
CVE-2025-11027MEDIUM5.4A vulnerability was identified in givanz Vvveb up to 1.0.7.2. Affected by this issue is some unknown functionality of th...
CVE-2025-6396MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webbeyaz We...
CVE-2025-57292MEDIUM6.1Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The applica...
CVE-2025-11019MEDIUM4.8A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Men...
CVE-2025-11017MEDIUM5.5A vulnerability was detected in OGRECave Ogre up to 14.4.1. The impacted element is the function Ogre::LogManager::strea...
CVE-2025-11016MEDIUM4.3A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileO...
CVE-2025-11015MEDIUM5.3A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the fil...
CVE-2025-11060MEDIUM5.7A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or gu...
CVE-2025-11025MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. V...
CVE-2025-11013MEDIUM5.5A vulnerability was identified in BehaviorTree up to 4.7.0. This vulnerability affects the function XMLParser::PImpl::lo...
CVE-2025-11011MEDIUM5.5A vulnerability was found in BehaviorTree up to 4.7.0. Affected by this issue is the function JsonExporter::fromJson of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now