2025 CVE Vulnerabilities

45,160 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-52344MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers to inject ...
CVE-2025-43791MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0...
CVE-2025-59328MEDIUM6.5A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the ins...
CVE-2025-59155MEDIUM6.9hackmd-mcp is a Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants. From 1.4...
CVE-2025-58177MEDIUM5.4n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scriptin...
CVE-2025-58172MEDIUM5.3drawnix is an all in one open-source whiteboard tool. In drawnix versions through 0.2.1, a cross-site scripting (XSS) vu...
CVE-2025-57176MEDIUM6.5On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpip...
CVE-2025-57104MEDIUM5.4Teampel 5.1.6 is vulnerable to SQL Injection in /Common/login.aspx.
CVE-2025-49089MEDIUM6.3wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd...
CVE-2025-43792MEDIUM5.3Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 202...
CVE-2025-59397MEDIUM5Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.
CVE-2025-56252MEDIUM6.1Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute arbitrary code via a crafted...
CVE-2025-52048MEDIUM6.5In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py...
CVE-2025-8396MEDIUM6.9Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server o...
CVE-2025-59376MEDIUM5.3feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-writ...
CVE-2025-39801MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint comma...
CVE-2025-39800MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on unexpected eb generatio...
CVE-2025-43794MEDIUM4.8Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported version...
CVE-2025-9826MEDIUM5.4Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to caus...
CVE-2025-9084MEDIUM6.1Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to...
CVE-2025-9072MEDIUM5.4Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, a...
CVE-2025-10441MEDIUM6.3A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the...
CVE-2025-9078MEDIUM4.3Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to ...
CVE-2025-9076MEDIUM6.5Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronizat...
CVE-2025-10440MEDIUM6.3A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now