2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12101MEDIUM5.9Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN vir...
CVE-2025-11862HIGH8.4A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and de...
CVE-2025-11697HIGH8.9A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability a...
CVE-2025-11696HIGH8.9A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. ...
CVE-2025-11085HIGH8.6A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in t...
CVE-2025-11084HIGH7.6A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a val...
CVE-2025-8324CRITICAL9.8Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the ...
CVE-2025-41106MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-41105MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-41104MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-41103MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-10161HIGH7.3Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on ...
CVE-2025-41102MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-41101MEDIUM5.4HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du...
CVE-2025-11960MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Softw...
CVE-2025-7633MEDIUM6.1Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t...
CVE-2025-7632MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t...
CVE-2025-7430MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t...
CVE-2025-12953MEDIUM4.3The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to una...
CVE-2025-12846HIGH8.8The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, a...
CVE-2025-12788MEDIUM5.3The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment veri...
CVE-2025-12787MEDIUM5.3The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking...
CVE-2025-12539CRITICAL10The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2025-9524MEDIUM4.3The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usabilit...
CVE-2025-9055MEDIUM6.4The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain L...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now