2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36116MEDIUM6.3IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a sp...
CVE-2025-54090MEDIUM6.3A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recomm...
CVE-2025-4411MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom In...
CVE-2025-54295MEDIUM5.1A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.
CVE-2025-4296MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing. This iss...
CVE-2025-27930MEDIUM5.4Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in th...
CVE-2025-53882MEDIUM4.8A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3...
CVE-2025-6174MEDIUM6.1The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_styleshe...
CVE-2025-43881MEDIUM5.3Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. ...
CVE-2025-42947MEDIUM5.5SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be execute...
CVE-2025-6261MEDIUM6.4The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetw...
CVE-2025-6215MEDIUM5.3The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and includ...
CVE-2025-6214MEDIUM6.5The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all ver...
CVE-2025-6054MEDIUM6.1The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-5818MEDIUM5.5The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forg...
CVE-2025-5753MEDIUM6.4The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in a...
CVE-2025-54139MEDIUM6.1HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 ...
CVE-2025-43489MEDIUM5.2A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu...
CVE-2025-43488MEDIUM4.8A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu...
CVE-2025-43487MEDIUM6.8A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions...
CVE-2025-43486MEDIUM4.8A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior...
CVE-2025-43485MEDIUM4.5A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu...
CVE-2025-43484MEDIUM6.1A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions pr...
CVE-2025-43483MEDIUM5.7A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu...
CVE-2025-43021MEDIUM5.7A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now