2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-57884MEDIUM4.3Missing Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting ...
CVE-2025-9341MEDIUM5.9Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips ...
CVE-2025-8678MEDIUM5.9The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via...
CVE-2025-41452MEDIUM6.8Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Ser...
CVE-2025-43752MEDIUM6.5Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-43753MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2...
CVE-2025-43747MEDIUM6.5A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure...
CVE-2025-55229MEDIUM5.3Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoo...
CVE-2025-55107MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11...
CVE-2025-55106MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t...
CVE-2025-55105MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t...
CVE-2025-55104MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists ArcGIS HUB and ArcGIS Enterprise Sites which allows an authenti...
CVE-2025-55103MEDIUM4.8There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Sites versions 10.9.1 – 11.4 t...
CVE-2025-27714MEDIUM6.3An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unaut...
CVE-2025-24489MEDIUM6.3An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to s...
CVE-2025-38742MEDIUM5.3Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Res...
CVE-2025-57768MEDIUM6.9Phproject is a high performance full-featured project management system. From 1.8.0 to before 1.8.3, a Stored Cross-Site...
CVE-2025-43754MEDIUM5.3Username enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4....
CVE-2025-8402MEDIUM4.9Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to ...
CVE-2025-7969MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it...
CVE-2025-6465MEDIUM4.3Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names...
CVE-2025-57763MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Reflected Cross-Site Scripting (XSS) vuln...
CVE-2025-57762MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Stored Cross-Site Scripting (XSS) vulnera...
CVE-2025-55522MEDIUM6.5Cross-site scripting (XSS) vulnerability in the component /common/reports of Akaunting v3.1.18 allows attackers to execu...
CVE-2025-55521MEDIUM6.5An issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now