2025 CVE Vulnerabilities

45,199 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-49193MEDIUM6.1The application fails to implement several security headers. These headers help increase the overall security level of t...
CVE-2025-49192MEDIUM6.1The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an atta...
CVE-2025-49191MEDIUM6.1Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded...
CVE-2025-49190MEDIUM5.8The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal req...
CVE-2025-49189MEDIUM6.1The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via cl...
CVE-2025-49187MEDIUM5.3For failed login attempts, the application returns different error messages depending on whether the login failed due to...
CVE-2025-49186MEDIUM6.5The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short tim...
CVE-2025-49185MEDIUM5.4The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can...
CVE-2025-5195MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2025-5996MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and...
CVE-2025-2254MEDIUM6.1An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and ...
CVE-2025-6003MEDIUM5.3The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capa...
CVE-2025-5301MEDIUM6.1ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS...
CVE-2025-40592MEDIUM6.1A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix Studio Pro 10.12 (All vers...
CVE-2025-32466MEDIUM6.7A SQL injection vulnerability in RSMediaGallery! component 1.7.4 - 2.1.7 for Joomla was discovered. The issue occurs wit...
CVE-2025-49150MEDIUM5.9Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enab...
CVE-2025-0923MEDIUM5.3IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source co...
CVE-2025-0917MEDIUM4.8IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to...
CVE-2025-0913MEDIUM5.5os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a danglin...
CVE-2025-4673MEDIUM6.8Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive inf...
CVE-2025-26383MEDIUM6.3The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized d...
CVE-2025-49146MEDIUM5.9pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is config...
CVE-2025-48448MEDIUM6.5Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocati...
CVE-2025-48444MEDIUM5.3Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Bl...
CVE-2025-48013MEDIUM5.3Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Bl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now