2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-51510MEDIUM4.9MoonShine was discovered to contain a SQL injection vulnerability under the Blog -> Categories page when using the moons...
CVE-2025-51489MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upl...
CVE-2025-51488MEDIUM4.9A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to sto...
CVE-2025-51487MEDIUM4.5A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary Ja...
CVE-2025-50897MEDIUM4.3A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical ...
CVE-2025-50579MEDIUM5.3A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularl...
CVE-2025-50461MEDIUM6.5A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script wh...
CVE-2025-4690MEDIUM4.3A regular expression used by AngularJS'  linky https://docs.angularjs.org/api/ngSanitize/filter/linky  filter to detect ...
CVE-2025-43739MEDIUM4.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-9139MEDIUM6.5A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the f...
CVE-2025-9138MEDIUM5.4A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Perform...
CVE-2025-9137MEDIUM4.8A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm....
CVE-2025-43740MEDIUM5.4A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0...
CVE-2025-9135MEDIUM5.5A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 1...
CVE-2025-9134MEDIUM5.5A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected elemen...
CVE-2025-8783MEDIUM4.4The Contact Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title’ parameter in all v...
CVE-2025-8567MEDIUM6.4The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions...
CVE-2025-41685MEDIUM6.5A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's...
CVE-2025-8622MEDIUM6.4The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortc...
CVE-2025-8357MEDIUM4.3The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads dir...
CVE-2025-5417MEDIUM6.1An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image....
CVE-2025-7496MEDIUM6.4The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements...
CVE-2025-54862MEDIUM5.4Sante PACS Server web portal is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes...
CVE-2025-54759MEDIUM6.1Sante PACS Server is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirectin...
CVE-2025-55590MEDIUM6.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bup...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now