2025 CVE Vulnerabilities

45,346 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54144MEDIUM5.4The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitra...
CVE-2025-9157MEDIUM5.3A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_pack...
CVE-2025-55740MEDIUM6.5nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engine...
CVE-2025-55737MEDIUM6.5flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ow...
CVE-2025-52337MEDIUM6.5An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5...
CVE-2025-50926MEDIUM6.5Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2025-43744MEDIUM5.4A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2...
CVE-2025-43743MEDIUM4.3Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q...
CVE-2025-2988MEDIUM6.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 ...
CVE-2025-55736MEDIUM6.5flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving...
CVE-2025-55735MEDIUM5.4flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the conte...
CVE-2025-55734MEDIUM6.5flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when vis...
CVE-2025-55303MEDIUM6.1Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimiza...
CVE-2025-52338MEDIUM5.3An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows...
CVE-2025-43745MEDIUM6.5A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 t...
CVE-2025-43737MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through ...
CVE-2025-33008MEDIUM5.4IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vu...
CVE-2025-31988MEDIUM4.8HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
CVE-2025-9151MEDIUM6.3A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the funct...
CVE-2025-55295MEDIUM6.5qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability e...
CVE-2025-9148MEDIUM6.3A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/se...
CVE-2025-9147MEDIUM6.1A vulnerability has been found in jasonclark getsemantic up to 040c96eb8cf9947488bd01b8de99b607b0519f7d. The impacted el...
CVE-2025-54881MEDIUM5.3Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ...
CVE-2025-54880MEDIUM6.1Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ...
CVE-2025-54411MEDIUM5.4Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now