2025 CVE Vulnerabilities

45,165 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-45585MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attacke...
CVE-2025-43795MEDIUM6.1Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 ...
CVE-2025-10322MEDIUM5.5A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sy...
CVE-2025-10321MEDIUM5.5A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Exec...
CVE-2025-56467MEDIUM6.5An issue was discovered in AXIS BANK LIMITED Axis Mobile App 9.9 that allows attackers to obtain sensitive information w...
CVE-2025-52074MEDIUM6.1PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in t...
CVE-2025-43787MEDIUM5.4A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2...
CVE-2025-39798MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: NFS: Fix the setting of capabilities when automount...
CVE-2025-39795MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: block: avoid possible overflow for chunk_sectors ch...
CVE-2025-39794MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ARM: tegra: Use I/O memcpy to write to IRAM Kasan ...
CVE-2025-39792MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dm: Always split write BIOs to zoned device limits ...
CVE-2025-55996MEDIUM6.3Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface
CVE-2025-10319MEDIUM6.5A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of th...
CVE-2025-59139MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw...
CVE-2025-59058MEDIUM5.9httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signatur...
CVE-2025-27233MEDIUM5.7Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex...
CVE-2025-10267MEDIUM6.9NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote at...
CVE-2025-8280MEDIUM5.8The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before...
CVE-2025-7337MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3...
CVE-2025-6769MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-58781MEDIUM6.3WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor en...
CVE-2025-1250MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-10148MEDIUM5.3curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Ins...
CVE-2025-10288MEDIUM5.5A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is a...
CVE-2025-10094MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now