2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10247MEDIUM6.3A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of ...
CVE-2025-9910MEDIUM4.7Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeB...
CVE-2025-9776MEDIUM6.5The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Inje...
CVE-2025-10245MEDIUM4.3A security flaw has been discovered in Display Painéis TGA up to 7.1.41. Affected by this issue is some unknown function...
CVE-2025-10235MEDIUM4.8A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm o...
CVE-2025-10234MEDIUM4.8A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point...
CVE-2025-10233MEDIUM4.3A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the f...
CVE-2025-10232MEDIUM5.4A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the fil...
CVE-2025-10229MEDIUM4.3A vulnerability has been found in Freshwork up to 1.2.3. This impacts an unknown function of the file /api/v2/logout. Su...
CVE-2025-43783MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3...
CVE-2025-10211MEDIUM6.3A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectCo...
CVE-2025-9714MEDIUM5.5Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to caus...
CVE-2025-43784MEDIUM6.5Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024...
CVE-2025-10209MEDIUM5.4A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the com...
CVE-2025-57520MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and d...
CVE-2025-43785MEDIUM6.1Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and Liferay DXP 2024 Q2.0 ...
CVE-2025-8681MEDIUM5.4Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component.  Requi...
CVE-2025-59035MEDIUM5.4Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior t...
CVE-2025-59034MEDIUM4.3Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior t...
CVE-2025-57573MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the wifiTimeClose parameter in goform/setWifi...
CVE-2025-57572MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentC...
CVE-2025-57571MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT...
CVE-2025-57570MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS.
CVE-2025-57569MEDIUM5.6Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT.
CVE-2025-43938MEDIUM4.4Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnera...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now