2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-49389MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Solutions Noti...
CVE-2025-47650MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global...
CVE-2025-28977MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes...
CVE-2025-9202MEDIUM4.3The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2025-8618MEDIUM6.4The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2025-55706MEDIUM5.1URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, a...
CVE-2025-54551MEDIUM5.3Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control...
CVE-2025-53522MEDIUM6.9Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be ...
CVE-2025-57791MEDIUM6.5A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments...
CVE-2025-57789MEDIUM5.4During the brief window between installation and the first administrator login, remote attackers may exploit the default...
CVE-2025-57788MEDIUM6.5A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user ...
CVE-2025-54364MEDIUM6.9Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_des...
CVE-2025-54363MEDIUM6.9Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_fu...
CVE-2025-9171MEDIUM5.4A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file...
CVE-2025-9170MEDIUM5.4A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax...
CVE-2025-9169MEDIUM5.4A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the c...
CVE-2025-9186MEDIUM6.5Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.
CVE-2025-9183MEDIUM6.5Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.
CVE-2025-9181MEDIUM6.5Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14...
CVE-2025-9168MEDIUM5.4A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice o...
CVE-2025-9167MEDIUM5.4A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice...
CVE-2025-8364MEDIUM4.3A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack....
CVE-2025-8041MEDIUM5.3In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. T...
CVE-2025-55033MEDIUM6.1Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially result...
CVE-2025-55032MEDIUM6.1Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the conten...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now