2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7462MEDIUM5.3A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as ...
CVE-2025-53636MEDIUM5.4Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many e...
CVE-2025-7452MEDIUM6.3A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as cr...
CVE-2025-53642MEDIUM6.5haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a us...
CVE-2025-7450MEDIUM5.4A vulnerability was found in letseeqiji gorobbs up to 1.0.8. It has been classified as critical. This affects the functi...
CVE-2025-47964MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2025-47963MEDIUM6.5No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a netw...
CVE-2025-47182MEDIUM5.6Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature ...
CVE-2025-45582MEDIUM4.1GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step proc...
CVE-2025-6549MEDIUM6.9An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthen...
CVE-2025-52989MEDIUM6.8An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allow...
CVE-2025-52986MEDIUM6.8A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Netwo...
CVE-2025-52985MEDIUM6.9A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an...
CVE-2025-52994MEDIUM4.9gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. ...
CVE-2025-52963MEDIUM6.8An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-pri...
CVE-2025-52958MEDIUM6A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolv...
CVE-2025-52951MEDIUM6.9A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker...
CVE-2025-48924MEDIUM5.3Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with comm...
CVE-2025-6788MEDIUM5.3A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong co...
CVE-2025-50125MEDIUM6.3A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execu...
CVE-2025-3933MEDIUM5.3A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp...
CVE-2025-6851MEDIUM6.5The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...
CVE-2025-6838MEDIUM4.1The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0...
CVE-2025-6438MEDIUM5.9A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulati...
CVE-2025-6745MEDIUM5.3The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now