2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54240MEDIUM5.5After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-54239MEDIUM5.5After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-54083MEDIUM5.1Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows admin acc...
CVE-2025-44595MEDIUM6.1Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.
CVE-2025-44593MEDIUM6.1Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. S...
CVE-2025-34178MEDIUM5.4In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-relate...
CVE-2025-34177MEDIUM5.4In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-relate...
CVE-2025-34176MEDIUM4.3In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory trav...
CVE-2025-58759MEDIUM6.5TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly s...
CVE-2025-58442MEDIUM5.3Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in ...
CVE-2025-58435MEDIUM4.1Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not c...
CVE-2025-58430MEDIUM6.1listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every...
CVE-2025-55054MEDIUM6.1CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55053MEDIUM6.5CWE-328: Use of Weak Hash
CVE-2025-54255MEDIUM4Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Desig...
CVE-2025-47415MEDIUM6.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x7...
CVE-2025-43786MEDIUM5.3Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q...
CVE-2025-36125MEDIUM5.4IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This v...
CVE-2025-36011MEDIUM4.3IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or se...
CVE-2025-34175MEDIUM6.1In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed ...
CVE-2025-34174MEDIUM5.4In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a nume...
CVE-2025-34173MEDIUM4.3In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of direct...
CVE-2025-34172MEDIUM6.1In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed af...
CVE-2025-55052MEDIUM4.3CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-43781MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now