2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-31269MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26...
CVE-2025-31268MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma ...
CVE-2025-31254MEDIUM5.4This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processin...
CVE-2025-30468MEDIUM6.5This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsin...
CVE-2025-24197MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Ta...
CVE-2025-10485MEDIUM4.3A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue i...
CVE-2025-6999MEDIUM6.9An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote...
CVE-2025-6947MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi...
CVE-2025-57117MEDIUM5.4A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execut...
CVE-2025-43802MEDIUM6.1Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint in Liferay Portal 7...
CVE-2025-43797MEDIUM5.4In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update...
CVE-2025-43799MEDIUM6.5Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202...
CVE-2025-43798MEDIUM6.5Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-...
CVE-2025-59154MEDIUM5.9Openfire is an XMPP server licensed under the Open Source Apache License. Openfire’s SASL EXTERNAL mechanism for client ...
CVE-2025-56448MEDIUM6.8The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling...
CVE-2025-45091MEDIUM5.4Seafile versions 11.0.18-Pro, 12.0.10, and 12.0.10-Pro are vulnerable to a stored Cross-Site Scripting (XSS) attack. An ...
CVE-2025-10475MEDIUM5.5A weakness has been identified in SpyShelter up to 15.4.0.1015. Affected is an unknown function in the library SpyShelte...
CVE-2025-43800MEDIUM6.1Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q...
CVE-2025-52344MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers to inject ...
CVE-2025-43791MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0...
CVE-2025-59328MEDIUM6.5A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the ins...
CVE-2025-59155MEDIUM6.9hackmd-mcp is a Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants. From 1.4...
CVE-2025-58177MEDIUM5.4n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scriptin...
CVE-2025-58172MEDIUM5.3drawnix is an all in one open-source whiteboard tool. In drawnix versions through 0.2.1, a cross-site scripting (XSS) vu...
CVE-2025-57176MEDIUM6.5On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpip...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now