2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58114MEDIUM4.8Improper Input Validation vulnerability in Hallo Welt! GmbH BlueSpice (Extension:CognitiveProcessDesigner) allows Cross-...
CVE-2025-57880MEDIUM5.4Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) all...
CVE-2025-48007MEDIUM6.4Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows ...
CVE-2025-46703MEDIUM6.4Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-...
CVE-2025-10715MEDIUM5.3A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an ...
CVE-2025-10711MEDIUM4.3A vulnerability has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This vulnerability affects unknown co...
CVE-2025-10710MEDIUM4.3A flaw has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This affects an unknown part of the file /inde...
CVE-2025-8531MEDIUM6.8Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03...
CVE-2025-10719MEDIUM5.3Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers wit...
CVE-2025-10630MEDIUM4.3Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to ...
CVE-2025-7702MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry ...
CVE-2025-7403MEDIUM6.5Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes a...
CVE-2025-10456MEDIUM6.5A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specif...
CVE-2025-10146MEDIUM6.1The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter i...
CVE-2025-8487MEDIUM5.4The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capabi...
CVE-2025-59715MEDIUM5.4SMSEagle before 6.11 allows reflected XSS via a username or contact phone number.
CVE-2025-59714MEDIUM4.9In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.
CVE-2025-59712MEDIUM5.4Snipe-IT before 8.1.18 allows XSS.
CVE-2025-30755MEDIUM6.1OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens t...
CVE-2025-47906MEDIUM6.5If the PATH environment variable contains paths which are executables (rather than just directories), passing certain st...
CVE-2025-26503MEDIUM6.7A crafted system call argument can cause memory corruption.
CVE-2025-36146MEDIUM4.3IBM Lakehouse (watsonx.data 2.2) could allow an authenticated user to obtain sensitive server component version informat...
CVE-2025-36139MEDIUM4.8IBM Lakehouse (watsonx.data 2.2) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged us...
CVE-2025-10676MEDIUM4.3A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /b...
CVE-2025-10675MEDIUM4.3A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now