2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53581MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in artiosmedia RSS Fe...
CVE-2025-53347MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium kalium allows Cross Site Request Forgery.This issue ...
CVE-2025-53343MEDIUM4.3Missing Authorization vulnerability in GoodLayers Modernize modernize allows Exploiting Incorrectly Configured Access Co...
CVE-2025-53342MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoodLayers Moderni...
CVE-2025-53341MEDIUM4.3Missing Authorization vulnerability in Themovation App, SaaS & Software Startup Tech Theme - Stratus stratusx allows Exp...
CVE-2025-53330MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpEstate WP Rental...
CVE-2025-53249MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online build-app-online allows Cross Site Reques...
CVE-2025-53241MEDIUM5.5Server-Side Request Forgery (SSRF) vulnerability in kodeshpa Simplified simplified allows Server Side Request Forgery.Th...
CVE-2025-53221MEDIUM4.3Missing Authorization vulnerability in codeablepress CodeablePress codeablepress-simple-frontend-profile-picture-upload ...
CVE-2025-53219MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools wp-database-optimizer-tools allows ...
CVE-2025-52771MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bcupham Video Expa...
CVE-2025-52769MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in flexostudio flexo-social-gallery flexo-social-gallery allows Cross Si...
CVE-2025-52767MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analyt...
CVE-2025-52335MEDIUM6.1EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive inform...
CVE-2025-21110MEDIUM4.4Dell Data Lakehouse, versions prior to 1.5.0.0, contains an Execution with Unnecessary Privileges vulnerability. A high ...
CVE-2025-9043MEDIUM6.7The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin p...
CVE-2025-9039MEDIUM5.3We identified an issue in the Amazon ECS agent where, under certain conditions, an introspection server could be accesse...
CVE-2025-50817MEDIUM5.4A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a fil...
CVE-2025-50515MEDIUM6.5An issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitr...
CVE-2025-20306MEDIUM4.9A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al...
CVE-2025-20302MEDIUM4.3A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-pri...
CVE-2025-20301MEDIUM6.5A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-pri...
CVE-2025-20268MEDIUM5.8A vulnerability in the Geolocation-Based Remote Access (RA) VPN feature of Cisco Secure Firewall Threat Defense (FTD) So...
CVE-2025-20254MEDIUM5.8A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Applian...
CVE-2025-20252MEDIUM5.8A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Applian...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now