2025 CVE Vulnerabilities

45,187 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4775MEDIUM6.4The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-48993MEDIUM6.1Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27...
CVE-2025-48992MEDIUM4.8Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27...
CVE-2025-6142MEDIUM6.3A vulnerability was found in Intera InHire up to 20250530. It has been declared as critical. Affected by this vulnerabil...
CVE-2025-6141MEDIUM4.8A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affec...
CVE-2025-43200MEDIUM4.2This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPad...
CVE-2025-27587MEDIUM5.3OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the ...
CVE-2025-49134MEDIUM5.3Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP addres...
CVE-2025-47951MEDIUM4.9Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject t...
CVE-2025-6131MEDIUM4.8A vulnerability, which was classified as problematic, was found in CodeAstro Food Ordering System 1.0. Affected is an un...
CVE-2025-2327MEDIUM5.1A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.
CVE-2025-6127MEDIUM5.4A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Aff...
CVE-2025-6126MEDIUM5.4A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected b...
CVE-2025-4565MEDIUM5.3Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary numb...
CVE-2025-6125MEDIUM5.4A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected...
CVE-2025-6120MEDIUM5.3A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulne...
CVE-2025-46710MEDIUM5.7Possible kernel exceptions caused by reading and writing kernel heap data after free.
CVE-2025-6119MEDIUM5.3A vulnerability classified as critical has been found in Open Asset Import Library Assimp up to 5.4.3. Affected is the f...
CVE-2025-4748MEDIUM4.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modul...
CVE-2025-25265MEDIUM4.9A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a...
CVE-2025-25264MEDIUM6.5An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The curr...
CVE-2025-40729MEDIUM6.1Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote...
CVE-2025-40727MEDIUM5.1A Reflected Cross Site Scripting (XSS) vulnerability was found in '/search' in Phoenix Site CMS from Phoenix, which allo...
CVE-2025-40726MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in /pages/search-results-page in Nosto, which allows remote attackers...
CVE-2025-2091MEDIUM5.4An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows atta...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now