2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4411MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom In...
CVE-2025-54295MEDIUM5.1A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.
CVE-2025-4296MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing. This iss...
CVE-2025-27930MEDIUM5.4Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in th...
CVE-2025-53882MEDIUM4.8A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3...
CVE-2025-6174MEDIUM6.1The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_styleshe...
CVE-2025-43881MEDIUM5.3Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. ...
CVE-2025-42947MEDIUM5.5SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be execute...
CVE-2025-6261MEDIUM6.4The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetw...
CVE-2025-6215MEDIUM5.3The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and includ...
CVE-2025-6214MEDIUM6.5The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all ver...
CVE-2025-6054MEDIUM6.1The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2025-5818MEDIUM5.5The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forg...
CVE-2025-5753MEDIUM6.4The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in a...
CVE-2025-54139MEDIUM6.1HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 ...
CVE-2025-43489MEDIUM5.2A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu...
CVE-2025-43488MEDIUM4.8A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu...
CVE-2025-43487MEDIUM6.8A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions...
CVE-2025-43486MEDIUM4.8A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior...
CVE-2025-43485MEDIUM4.5A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu...
CVE-2025-43484MEDIUM6.1A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions pr...
CVE-2025-43483MEDIUM5.7A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu...
CVE-2025-43021MEDIUM5.7A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu...
CVE-2025-43020MEDIUM6.8A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12....
CVE-2025-8033MEDIUM6.5The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now