2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48382MEDIUM5.5Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fes...
CVE-2025-48054MEDIUM6.8Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnera...
CVE-2025-4683MEDIUM4.3The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modifi...
CVE-2025-4682MEDIUM6.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2025-33079MEDIUM6.5IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials ...
CVE-2025-4783MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attrib...
CVE-2025-46802MEDIUM6For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.
CVE-2025-23392MEDIUM5.6A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows e...
CVE-2025-46803MEDIUM5.1The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone t...
CVE-2025-37992MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net_sched: Flush gso_skb list too during ->change()...
CVE-2025-46805MEDIUM5.7Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to pr...
CVE-2025-39498MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) al...
CVE-2025-5185MEDIUM5.3A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been declared as...
CVE-2025-40667MEDIUM6.5Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionalit...
CVE-2025-40663MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in i2A-Cronos version 23.02.01.17, from i2A. It allows an authenticated ...
CVE-2025-40653MEDIUM6.9User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a differen...
CVE-2025-40652MEDIUM5.3Stored Cross-Site Scripting (XSS) vulnerability in the CoverManager booking software. This allows an attacker to inject ...
CVE-2025-5183MEDIUM4.7A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as proble...
CVE-2025-5181MEDIUM4.1A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platfor...
CVE-2025-5177MEDIUM4.7A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This...
CVE-2025-4057MEDIUM5.5A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between se...
CVE-2025-4053MEDIUM6.8The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel gues...
CVE-2025-1985MEDIUM6.1Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject H...
CVE-2025-5175MEDIUM5.5A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the functio...
CVE-2025-41441MEDIUM5.3Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unau...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now