2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53902MEDIUM4.3Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com...
CVE-2025-53541MEDIUM5.4Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com...
CVE-2025-52899MEDIUM5.3Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Com...
CVE-2025-51045MEDIUM6.5Phpgurukul Pre-School Enrollment System 1.0 contains a SQL injection vulnerability in the /admin/password-recovery.php f...
CVE-2025-51044MEDIUM6.5phpgurukul Nipah virus (NiV) Testing Management System 1.0 contains a SQL injection vulnerability in the /new-user-testi...
CVE-2025-52284MEDIUM6.5Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 functio...
CVE-2025-2179MEDIUM6.8An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a ...
CVE-2025-27514MEDIUM5.4GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2025-5922MEDIUM4.8Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and r...
CVE-2025-28171MEDIUM6.5An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the ...
CVE-2025-28172MEDIUM6.5Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Att...
CVE-2025-52358MEDIUM6.3A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Lo...
CVE-2025-6060MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Softwa...
CVE-2025-54422MEDIUM5.5Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1....
CVE-2025-41241MEDIUM4.4VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and ha...
CVE-2025-40686MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ...
CVE-2025-40685MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ...
CVE-2025-40684MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ...
CVE-2025-40683MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an ...
CVE-2025-5587MEDIUM6.4The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in al...
CVE-2025-8216MEDIUM6.4The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in a...
CVE-2025-8196MEDIUM6.4The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cust...
CVE-2025-6730MEDIUM4.3The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2025-6692MEDIUM6.4The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all ...
CVE-2025-6681MEDIUM6.4The Fan Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now