2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2183MEDIUM5.3An insufficient certificate validation issue in the Palo Alto Networks GlobalProtect™ app enables attackers to connect t...
CVE-2025-2182MEDIUM5.6A problem with the implementation of the MACsec protocol in Palo Alto Networks PAN-OS® results in the cleartext exposure...
CVE-2025-2181MEDIUM5.9A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleart...
CVE-2025-2180MEDIUM4.8An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to e...
CVE-2025-8918MEDIUM4.8A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /int...
CVE-2025-54500MEDIUM5.3An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to bre...
CVE-2025-53859MEDIUM6.3NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated at...
CVE-2025-51691MEDIUM6.1Cross-Site Scripting (XSS) vulnerability found in MarkTwo commit e3a1d3f90cce4ea9c26efcbbf3a1cbfb9dcdb298 (May 2025) all...
CVE-2025-50690MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in SpatialReference.org (OSGeo/spatialreference.org) versions prior to...
CVE-2025-55668MEDIUM6.5Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 thr...
CVE-2025-55160MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2025-55005MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1,...
CVE-2025-55004MEDIUM4.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1,...
CVE-2025-54791MEDIUM5.3OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when rese...
CVE-2025-52392MEDIUM5.4Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout m...
CVE-2025-52386MEDIUM5.4CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file
CVE-2025-55280MEDIUM5.2This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plai...
CVE-2025-55279MEDIUM6.9This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. A...
CVE-2025-54465MEDIUM6.8This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the...
CVE-2025-8916MEDIUM6.3Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on...
CVE-2025-8911MEDIUM6.1Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthen...
CVE-2025-8910MEDIUM6.1Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthen...
CVE-2025-8762MEDIUM6.8A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the comp...
CVE-2025-8891MEDIUM4.3The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to m...
CVE-2025-8491MEDIUM4.3The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now