2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36064MEDIUM5.9IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate account lockout setting t...
CVE-2025-59418MEDIUM5.5BunnyPad is a note taking software. Prior to version 11.0.27000.0915, opening files greater than or equal to 20MB causes...
CVE-2025-57438MEDIUM6.8The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intend...
CVE-2025-55886MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` paramete...
CVE-2025-55885MEDIUM6.3SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote atta...
CVE-2025-59413MEDIUM6.5CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription ...
CVE-2025-59412MEDIUM5.4CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews featu...
CVE-2025-59411MEDIUM5.4CubeCart is an ecommerce software solution. Prior to version 6.5.11, the contact form’s Enquiry field accepts raw HTML a...
CVE-2025-43807MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, a...
CVE-2025-57682MEDIUM6.5Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary fil...
CVE-2025-57433MEDIUM6.5The 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POS...
CVE-2025-36037MEDIUM5.4IBM webMethods Integration 10.15 and 11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authe...
CVE-2025-56075MEDIUM5.4A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing...
CVE-2025-59797MEDIUM5.8Profession Fit 5.0.99 Build 44910 allows authorization bypass via a direct request for /api/challenges/{id} and also URL...
CVE-2025-46711MEDIUM5.5Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger NULL pointer derefe...
CVE-2025-10794MEDIUM6.1A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the ...
CVE-2025-9035MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Horato Inte...
CVE-2025-25177MEDIUM5.1Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2025-8079MEDIUM4.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akıllı Tica...
CVE-2025-0875MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. C...
CVE-2025-10787MEDIUM6.3A vulnerability was found in MuYuCMS up to 2.7. Impacted is an unknown function of the file /index/index.html of the com...
CVE-2025-9541MEDIUM4.7The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the ...
CVE-2025-9540MEDIUM4.7The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the ...
CVE-2025-9487MEDIUM4.7The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc...
CVE-2025-9115MEDIUM5.6The Etsy Shop WordPress plugin before 3.0.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now