2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-35431MEDIUM5.4CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify L...
CVE-2025-35430MEDIUM6.5CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'...
CVE-2025-9862MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue aff...
CVE-2025-57055MEDIUM6.5WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An ...
CVE-2025-54390MEDIUM6.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (...
CVE-2025-59476MEDIUM5.3Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted fr...
CVE-2025-59475MEDIUM4.3Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profil...
CVE-2025-59474MEDIUM5.3Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intent...
CVE-2025-55904MEDIUM4Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference wh...
CVE-2025-50709MEDIUM4.3An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter
CVE-2025-8463MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forcef...
CVE-2025-54467MEDIUM5.3When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the pass...
CVE-2025-53884MEDIUM5.3NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table a...
CVE-2025-0879MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shopside So...
CVE-2025-8999MEDIUM5.3The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t...
CVE-2025-0546MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Ren...
CVE-2025-10591MEDIUM5.4A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet...
CVE-2025-10590MEDIUM6.1A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of th...
CVE-2025-0420MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof...
CVE-2025-59456MEDIUM5.5In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
CVE-2025-59455MEDIUM4.2In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
CVE-2025-0419MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Infor...
CVE-2025-9565MEDIUM6.4The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newslet...
CVE-2025-9215MEDIUM6.5The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor...
CVE-2025-9203MEDIUM6.4The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now