2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-51990MEDIUM4.8XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administra...
CVE-2025-50864MEDIUM6.5An Origin Validation Error in the elysia-cors library thru 1.3.0 allows attackers to bypass Cross-Origin Resource Sharin...
CVE-2025-43748MEDIUM6.8Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 202...
CVE-2025-1142MEDIUM5.4IBM Edge Application Manager 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated at...
CVE-2025-1139MEDIUM4.4IBM Edge Application Manager 4.5 could allow a local user to read or modify resources that they should not have authoriz...
CVE-2025-8449MEDIUM4.1CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticat...
CVE-2025-55499MEDIUM6.5Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTi...
CVE-2025-54927MEDIUM4.9CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c...
CVE-2025-54175MEDIUM6.1QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality.  An attacker can c...
CVE-2025-54174MEDIUM4.3QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft spe...
CVE-2025-54172MEDIUM4.8QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin pri...
CVE-2025-4877MEDIUM4.5There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer ...
CVE-2025-4437MEDIUM5.7There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specify...
CVE-2025-43750MEDIUM6.5Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-43749MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-8102MEDIUM5.4The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-7777MEDIUM6.5The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker...
CVE-2025-43742MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-43741MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-57734MEDIUM6.5In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files
CVE-2025-57732MEDIUM6.3In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership
CVE-2025-57731MEDIUM5.4In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content
CVE-2025-57730MEDIUM4.6In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature
CVE-2025-57728MEDIUM6.5In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files
CVE-2025-9229MEDIUM5.3Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated att...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now