2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-3780MEDIUM6.5The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is...
CVE-2025-47120MEDIUM5.5Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that co...
CVE-2025-47119MEDIUM5.5Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could...
CVE-2025-49547MEDIUM5.4Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-49534MEDIUM5.4Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-49525MEDIUM5.5Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-49524MEDIUM5.5Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead...
CVE-2025-30313MEDIUM5.5Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-27165MEDIUM5.5Substance3D - Stager versions 3.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-7031MEDIUM5.3Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly C...
CVE-2025-7030MEDIUM6.5Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrec...
CVE-2025-49545MEDIUM6.2ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerabil...
CVE-2025-49544MEDIUM6.8ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-49543MEDIUM4.3ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili...
CVE-2025-49542MEDIUM5.2ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerab...
CVE-2025-49541MEDIUM4.3ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili...
CVE-2025-49540MEDIUM4.3ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerabili...
CVE-2025-49539MEDIUM4.5ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-43584MEDIUM5.5Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to di...
CVE-2025-43583MEDIUM5.5Substance3D - Viewer versions 0.22 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead ...
CVE-2025-48386MEDIUM6.3Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-...
CVE-2025-27369MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a ...
CVE-2025-27367MEDIUM6.5IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side v...
CVE-2025-7363MEDIUM5.4The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User i...
CVE-2025-7362MEDIUM5.4The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now