2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-55054MEDIUM6.1CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55053MEDIUM6.5CWE-328: Use of Weak Hash
CVE-2025-54255MEDIUM4Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Desig...
CVE-2025-47415MEDIUM6.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x7...
CVE-2025-43786MEDIUM5.3Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q...
CVE-2025-36125MEDIUM5.4IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This v...
CVE-2025-36011MEDIUM4.3IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or se...
CVE-2025-34175MEDIUM6.1In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed ...
CVE-2025-34174MEDIUM5.4In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a nume...
CVE-2025-34173MEDIUM4.3In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of direct...
CVE-2025-34172MEDIUM6.1In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed af...
CVE-2025-55052MEDIUM4.3CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-43781MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q...
CVE-2025-43775MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 thr...
CVE-2025-9269MEDIUM6.9A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark dev...
CVE-2025-57665MEDIUM6.4Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, cr...
CVE-2025-5500MEDIUM5.3A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file Andr...
CVE-2025-59005MEDIUM4.3Missing Authorization vulnerability in frenify Categorify categorify allows Exploiting Incorrectly Configured Access Con...
CVE-2025-58990MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLento...
CVE-2025-58989MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 D...
CVE-2025-58988MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Dolson My Tick...
CVE-2025-58987MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football ...
CVE-2025-58985MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Addition...
CVE-2025-58984MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welca...
CVE-2025-58983MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Lissa Incl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now