2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-8388MEDIUM6.4The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cro...
CVE-2025-10197MEDIUM6.3A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability...
CVE-2025-10195MEDIUM5.3A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManif...
CVE-2025-59044MEDIUM4.4Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs f...
CVE-2025-9997MEDIUM5.8CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2025-59036MEDIUM5.5Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the ...
CVE-2025-58135MEDIUM6.5Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a...
CVE-2025-58134MEDIUM4.3Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impa...
CVE-2025-58131MEDIUM6.6Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or b...
CVE-2025-49458MEDIUM6.5Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via net...
CVE-2025-9996MEDIUM5.8CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ...
CVE-2025-7746MEDIUM5.3CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that c...
CVE-2025-54241MEDIUM5.5After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-54240MEDIUM5.5After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-54239MEDIUM5.5After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-54083MEDIUM5.1Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin acc...
CVE-2025-44595MEDIUM6.1Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.
CVE-2025-44593MEDIUM6.1Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. S...
CVE-2025-34178MEDIUM5.4In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-relate...
CVE-2025-34177MEDIUM5.4In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-relate...
CVE-2025-34176MEDIUM4.3In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory trav...
CVE-2025-58759MEDIUM6.5TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly s...
CVE-2025-58442MEDIUM5.3Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in ...
CVE-2025-58435MEDIUM4.1Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not c...
CVE-2025-58430MEDIUM6.1listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now