2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-55030MEDIUM6.1Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the cont...
CVE-2025-55028MEDIUM6.5Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and all...
CVE-2025-54144MEDIUM5.4The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitra...
CVE-2025-9157MEDIUM5.3A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_pack...
CVE-2025-55740MEDIUM6.5nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engine...
CVE-2025-55737MEDIUM6.5flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ow...
CVE-2025-52337MEDIUM6.5An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5...
CVE-2025-50926MEDIUM6.5Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2025-43744MEDIUM5.4A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2...
CVE-2025-43743MEDIUM4.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-2988MEDIUM6.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 ...
CVE-2025-55736MEDIUM6.5flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving...
CVE-2025-55735MEDIUM5.4flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the conte...
CVE-2025-55734MEDIUM6.5flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when vis...
CVE-2025-55303MEDIUM6.1Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimiza...
CVE-2025-52338MEDIUM5.3An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows...
CVE-2025-43745MEDIUM6.5A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 t...
CVE-2025-43737MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through ...
CVE-2025-33008MEDIUM5.4IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vu...
CVE-2025-31988MEDIUM4.8HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
CVE-2025-9151MEDIUM6.3A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the funct...
CVE-2025-55295MEDIUM6.5qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability e...
CVE-2025-9148MEDIUM6.3A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/se...
CVE-2025-9147MEDIUM6.1A vulnerability has been found in jasonclark getsemantic up to 040c96eb8cf9947488bd01b8de99b607b0519f7d. The impacted el...
CVE-2025-54881MEDIUM5.3Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now