2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10590MEDIUM6.1A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of th...
CVE-2025-0420MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof...
CVE-2025-59456MEDIUM5.5In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
CVE-2025-59455MEDIUM4.2In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
CVE-2025-0419MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Infor...
CVE-2025-9565MEDIUM6.4The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newslet...
CVE-2025-9215MEDIUM6.5The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor...
CVE-2025-9203MEDIUM6.4The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitl...
CVE-2025-9818MEDIUM6.7A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided ...
CVE-2025-55075MEDIUM6.9Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled ...
CVE-2025-10584MEDIUM5.4A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/...
CVE-2025-10188MEDIUM5.4The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio...
CVE-2025-10125MEDIUM6.4The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shor...
CVE-2025-9891MEDIUM4.3The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-9851MEDIUM6.4The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar...
CVE-2025-9629MEDIUM4.3The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5...
CVE-2025-8394MEDIUM6.4The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_producti...
CVE-2025-8153MEDIUM5.1Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8...
CVE-2025-10166MEDIUM6.4The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twitter'...
CVE-2025-10050MEDIUM6.6The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up t...
CVE-2025-43804MEDIUM6.1Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP ...
CVE-2025-37131MEDIUM4.9A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to acc...
CVE-2025-37130MEDIUM6.5A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitr...
CVE-2025-37129MEDIUM6.7A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploi...
CVE-2025-37128MEDIUM6.8A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now