2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58982MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline Pixeline'...
CVE-2025-58981MEDIUM5.4Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker ...
CVE-2025-58980MEDIUM5.3Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Acc...
CVE-2025-58979MEDIUM5.3Missing Authorization vulnerability in BerqWP BerqWP searchpro allows Exploiting Incorrectly Configured Access Control S...
CVE-2025-58978MEDIUM5.3Missing Authorization vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Exploiting Inco...
CVE-2025-58977MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Rhys Wynne WP eBay Product Feeds ebay-feeds-for-wordpress allows Ser...
CVE-2025-58976MEDIUM4.3Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker ...
CVE-2025-58975MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Cross Site Re...
CVE-2025-57540MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter confi...
CVE-2025-57539MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Vir...
CVE-2025-57538MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of P...
CVE-2025-55226MEDIUM6.7Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an...
CVE-2025-55225MEDIUM6.5Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor...
CVE-2025-54917MEDIUM4.3Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a...
CVE-2025-54915MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-54901MEDIUM5.5Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-54252MEDIUM5.4Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability...
CVE-2025-54251MEDIUM4.3Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result ...
CVE-2025-54250MEDIUM4.9Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c...
CVE-2025-54249MEDIUM6.5Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabilit...
CVE-2025-54247MEDIUM6.5Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c...
CVE-2025-54246MEDIUM6.5Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that cou...
CVE-2025-54109MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...
CVE-2025-54107MEDIUM4.3Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security fea...
CVE-2025-54104MEDIUM6.7Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now