2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58205MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader El...
CVE-2025-58204MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podc...
CVE-2025-58203MEDIUM4.4Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra solace-extra allows Server Side Request Forger...
CVE-2025-58202MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-acces...
CVE-2025-58201MEDIUM5.3Missing Authorization vulnerability in AfterShip & Automizely AfterShip Tracking aftership-woocommerce-tracking allows A...
CVE-2025-58198MEDIUM6.5Missing Authorization vulnerability in Xpro Xpro Theme Builder xpro-theme-builder allows Exploiting Incorrectly Configur...
CVE-2025-58197MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mra13 Simple Downl...
CVE-2025-58196MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uicore UiCore Elem...
CVE-2025-58195MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elemento...
CVE-2025-58194MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Pa...
CVE-2025-58193MEDIUM4.3Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Con...
CVE-2025-58192MEDIUM5.4Missing Authorization vulnerability in Xylus Themes WP Bulk Delete wp-bulk-delete allows Exploiting Incorrectly Configur...
CVE-2025-5187MEDIUM6.7A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete th...
CVE-2025-57821MEDIUM4.2Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.0, it is possible to craft a m...
CVE-2025-50977MEDIUM6.1A template injection vulnerability leading to reflected cross-site scripting (XSS) has been identified in version 1.7.1,...
CVE-2025-20348MEDIUM5A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co...
CVE-2025-20347MEDIUM5.4A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co...
CVE-2025-20342MEDIUM5.4A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll...
CVE-2025-20296MEDIUM5.4A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote...
CVE-2025-20295MEDIUM6A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrativ...
CVE-2025-20294MEDIUM6.5Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an auth...
CVE-2025-20292MEDIUM4.4A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute a command inj...
CVE-2025-20290MEDIUM5.5A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Se...
CVE-2025-20262MEDIUM5A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and C...
CVE-2025-54598MEDIUM6.5The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete al...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now