2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10822MEDIUM4.3A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogControlle...
CVE-2025-43814MEDIUM6.5In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, ...
CVE-2025-43810MEDIUM4.3Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.11...
CVE-2025-10821MEDIUM4.3A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of ...
CVE-2025-10820MEDIUM4.3A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /top...
CVE-2025-10819MEDIUM4.3A security vulnerability has been detected in fuyang_lipengjun platform 1.0. This issue affects the function UserCouponC...
CVE-2025-43806MEDIUM4.3Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2...
CVE-2025-59535MEDIUM6.5DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-57205MEDIUM5.4iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content...
CVE-2025-57204MEDIUM5.4Stocky POS with Inventory Management & HRM (ui-lib) version 5.0 is affected by a Stored Cross-Site Scripting (XSS) vulne...
CVE-2025-47910MEDIUM5.4When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than in...
CVE-2025-59433MEDIUM5.3Conventional Changelog generates changelogs and release notes from a project's commit messages and metadata. Prior to ve...
CVE-2025-59432MEDIUM6.6SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L...
CVE-2025-57203MEDIUM4.8MagicProject AI version 9.1 is affected by a Cross-Site Scripting (XSS) vulnerability within the chatbot generation feat...
CVE-2025-9960MEDIUM6.9A restriction bypass vulnerability in is-localhost-ip could allow attackers to perform Server-Side Request Forgery (SSRF...
CVE-2025-59592MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Acosta Ma...
CVE-2025-59591MEDIUM4.3Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access ...
CVE-2025-59590MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi...
CVE-2025-59589MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soleda...
CVE-2025-59587MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ...
CVE-2025-59586MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ...
CVE-2025-59585MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ...
CVE-2025-59584MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ...
CVE-2025-59583MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ...
CVE-2025-59582MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Darren Cooney Ajax Load More...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now