2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-43756MEDIUM5.4<!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scripting (XSS) vulnerabi...
CVE-2025-43755MEDIUM5.4A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, ...
CVE-2025-9308MEDIUM5.5A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/...
CVE-2025-9306MEDIUM5.4A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown...
CVE-2025-9162MEDIUM4.9A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes pla...
CVE-2025-57753MEDIUM6vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible...
CVE-2025-55744MEDIUM4.3UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some ...
CVE-2025-55742MEDIUM4.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPi...
CVE-2025-55371MEDIUM5.3Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers...
CVE-2025-50860MEDIUM5.4SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers ...
CVE-2025-55367MEDIUM5.3Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attacke...
CVE-2025-55366MEDIUM5.3Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily...
CVE-2025-51818MEDIUM5.4MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute ar...
CVE-2025-47184MEDIUM5.3An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 ...
CVE-2025-8064MEDIUM6.4The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘selector_height’ parame...
CVE-2025-8023MEDIUM4.9Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path trave...
CVE-2025-49810MEDIUM4.3Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thre...
CVE-2025-49222MEDIUM6.8Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to ...
CVE-2025-47870MEDIUM4.3Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team in...
CVE-2025-36530MEDIUM4.9Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate fi...
CVE-2025-8607MEDIUM6.4The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross...
CVE-2025-7221MEDIUM4.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2025-53505MEDIUM5.3Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerabil...
CVE-2025-53504MEDIUM5.4Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vuln...
CVE-2025-48355MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ProveSource LTD ProveSource ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now