2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36034MEDIUM5.9IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in...
CVE-2025-6698MEDIUM4.1A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been rated as problematic. Affected by this issue is so...
CVE-2025-6697MEDIUM4.1A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been declared as problematic. Affected by this vulnerab...
CVE-2025-6696MEDIUM4.1A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been classified as problematic. Affected is an unknown ...
CVE-2025-52902MEDIUM5.4File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52900MEDIUM5.5File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-6707MEDIUM5.4Under certain conditions, an authenticated user request may execute with stale privileges following an intentional chang...
CVE-2025-6695MEDIUM4.1A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This issue affects some unknown ...
CVE-2025-6694MEDIUM4.1A vulnerability has been found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This vulnerability affects ...
CVE-2025-6677MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs ...
CVE-2025-6676MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple XML ...
CVE-2025-6675MEDIUM4.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows ...
CVE-2025-6674MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Y...
CVE-2025-5682MEDIUM4.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki...
CVE-2025-52573MEDIUM6iOS Simulator MCP Server (ios-simulator-mcp) is a Model Context Protocol (MCP) server for interacting with iOS simulator...
CVE-2025-48923MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Toc.Js allo...
CVE-2025-48922MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GLightbox a...
CVE-2025-3773MEDIUM5.5A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authentic...
CVE-2025-3722MEDIUM4.4A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privi...
CVE-2025-6703MEDIUM6.5Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0...
CVE-2025-6212MEDIUM6.1The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database m...
CVE-2025-5842MEDIUM5.4The Modern Design Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in...
CVE-2025-5338MEDIUM5.4The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all...
CVE-2025-5846MEDIUM4.3An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1...
CVE-2025-5315MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now