2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54129MEDIUM4.3HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versio...
CVE-2025-54128MEDIUM6.1HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the ...
CVE-2025-7938MEDIUM4.3A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the ...
CVE-2025-7233MEDIUM5.5IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability a...
CVE-2025-54121MEDIUM5.3Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async w...
CVE-2025-51403MEDIUM6.5A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4....
CVE-2025-51401MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attacke...
CVE-2025-51400MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attac...
CVE-2025-51398MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows att...
CVE-2025-51397MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers...
CVE-2025-51396MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web sc...
CVE-2025-36057MEDIUM4.6IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authe...
CVE-2025-52575MEDIUM6.5EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulner...
CVE-2025-7716MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time S...
CVE-2025-7715MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Attri...
CVE-2025-7392MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookies Add...
CVE-2025-43720MEDIUM6.5Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is ex...
CVE-2025-36603MEDIUM4.8Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low...
CVE-2025-32744MEDIUM6.6Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high priv...
CVE-2025-30477MEDIUM4.9Dell PowerScale OneFS, versions prior to 9.11.0.0, contains a use of a broken or risky cryptographic algorithm vulnerabi...
CVE-2025-52374MEDIUM4.6Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passw...
CVE-2025-52373MEDIUM4.6Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwo...
CVE-2025-52372MEDIUM5.1An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation...
CVE-2025-46119MEDIUM6.3An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDir...
CVE-2025-46118MEDIUM5.3An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDire...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now