2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59342MEDIUM5.5esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw ...
CVE-2025-59339MEDIUM4.4The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording tt...
CVE-2025-58767MEDIUM5.3REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing...
CVE-2025-58431MEDIUM6.2ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earl...
CVE-2025-10607MEDIUM6.5A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the fil...
CVE-2025-10606MEDIUM6.1A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file...
CVE-2025-10605MEDIUM6.1A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the fi...
CVE-2025-35435MEDIUM5.3CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could caus...
CVE-2025-35431MEDIUM5.4CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify L...
CVE-2025-35430MEDIUM6.5CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'...
CVE-2025-9862MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue aff...
CVE-2025-57055MEDIUM6.5WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An ...
CVE-2025-54390MEDIUM6.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (...
CVE-2025-59476MEDIUM5.3Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted fr...
CVE-2025-59475MEDIUM4.3Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profil...
CVE-2025-59474MEDIUM5.3Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intent...
CVE-2025-55904MEDIUM4Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference wh...
CVE-2025-50709MEDIUM4.3An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter
CVE-2025-8463MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forcef...
CVE-2025-54467MEDIUM5.3When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the pass...
CVE-2025-53884MEDIUM5.3NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table a...
CVE-2025-0879MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shopside So...
CVE-2025-8999MEDIUM5.3The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t...
CVE-2025-0546MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Ren...
CVE-2025-10591MEDIUM5.4A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now