2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36116 | MEDIUM | 6.3 | 0.2% | Jul 23, 2025 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a sp... |
| CVE-2025-54090 | MEDIUM | 6.3 | 0.7% | Jul 23, 2025 | A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recomm... |
| CVE-2025-4411 | MEDIUM | 6.5 | 0.3% | Jul 23, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom In... |
| CVE-2025-54295 | MEDIUM | 5.1 | 0.3% | Jul 23, 2025 | A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered. |
| CVE-2025-4296 | MEDIUM | 4.7 | 0.2% | Jul 23, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing. This iss... |
| CVE-2025-27930 | MEDIUM | 5.4 | 0.4% | Jul 23, 2025 | Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in th... |
| CVE-2025-53882 | MEDIUM | 4.8 | 0.1% | Jul 23, 2025 | A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3... |
| CVE-2025-6174 | MEDIUM | 6.1 | 0.5% | Jul 23, 2025 | The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_styleshe... |
| CVE-2025-43881 | MEDIUM | 5.3 | 0.3% | Jul 23, 2025 | Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. ... |
| CVE-2025-42947 | MEDIUM | 5.5 | 0.3% | Jul 23, 2025 | SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be execute... |
| CVE-2025-6261 | MEDIUM | 6.4 | 0.2% | Jul 23, 2025 | The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetw... |
| CVE-2025-6215 | MEDIUM | 5.3 | 0.3% | Jul 23, 2025 | The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and includ... |
| CVE-2025-6214 | MEDIUM | 6.5 | 0.2% | Jul 23, 2025 | The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all ver... |
| CVE-2025-6054 | MEDIUM | 6.1 | 0.1% | Jul 23, 2025 | The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-5818 | MEDIUM | 5.5 | 0.3% | Jul 23, 2025 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forg... |
| CVE-2025-5753 | MEDIUM | 6.4 | 0.2% | Jul 23, 2025 | The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in a... |
| CVE-2025-54139 | MEDIUM | 6.1 | 0.3% | Jul 23, 2025 | HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 ... |
| CVE-2025-43489 | MEDIUM | 5.2 | 0.3% | Jul 23, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu... |
| CVE-2025-43488 | MEDIUM | 4.8 | 0.2% | Jul 23, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu... |
| CVE-2025-43487 | MEDIUM | 6.8 | 0.2% | Jul 23, 2025 | A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions... |
| CVE-2025-43486 | MEDIUM | 4.8 | 0.2% | Jul 23, 2025 | A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior... |
| CVE-2025-43485 | MEDIUM | 4.5 | 0.2% | Jul 23, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu... |
| CVE-2025-43484 | MEDIUM | 6.1 | 0.2% | Jul 23, 2025 | A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions pr... |
| CVE-2025-43483 | MEDIUM | 5.7 | 0.1% | Jul 23, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu... |
| CVE-2025-43021 | MEDIUM | 5.7 | 0.1% | Jul 22, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now