2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53463MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega...
CVE-2025-53462MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SAPO SAPO Feed sap...
CVE-2025-53461MEDIUM4.4Server-Side Request Forgery (SSRF) vulnerability in Binsaifullah Beaf image-compare-block allows Server Side Request For...
CVE-2025-53460MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Affili...
CVE-2025-53458MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davaxi Goracash go...
CVE-2025-53457MEDIUM4.4Server-Side Request Forgery (SSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Serv...
CVE-2025-53456MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in activewebsight SEO Backlink Monitor seo-backlink-monitor allows Cross...
CVE-2025-53455MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CashBill CashBill....
CVE-2025-53454MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimat...
CVE-2025-53452MEDIUM4.3Missing Authorization vulnerability in Barry Event Rocket allows Exploiting Incorrectly Configured Access Control Securi...
CVE-2025-53451MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in mihdan Mihdan: No External Links mihdan-no-external-links allows Cros...
CVE-2025-52367MEDIUM5.4Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the...
CVE-2025-36064MEDIUM5.9IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting t...
CVE-2025-59418MEDIUM5.5BunnyPad is a note taking software. Prior to version 11.0.27000.0915, opening files greater than or equal to 20MB causes...
CVE-2025-57438MEDIUM6.8The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intend...
CVE-2025-55886MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` paramete...
CVE-2025-55885MEDIUM6.3SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote atta...
CVE-2025-59413MEDIUM6.5CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription ...
CVE-2025-59412MEDIUM5.4CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews featu...
CVE-2025-59411MEDIUM5.4CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML a...
CVE-2025-43807MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, a...
CVE-2025-57682MEDIUM6.5Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary fil...
CVE-2025-57433MEDIUM6.5The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POS...
CVE-2025-36037MEDIUM5.4IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authe...
CVE-2025-56075MEDIUM5.4A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now