2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-0993MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 befor...
CVE-2025-0679MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2025-0605MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2025-4575MEDIUM6.5Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use f...
CVE-2025-3111MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and ...
CVE-2025-2853MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 befor...
CVE-2025-1110MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a...
CVE-2025-3939MEDIUM5.3Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enter...
CVE-2025-3444MEDIUM6.5Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated L...
CVE-2025-4419MEDIUM4.3The Hot Random Image plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.9.2 vi...
CVE-2025-4405MEDIUM5.4The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all v...
CVE-2025-4280MEDIUM4.8MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissi...
CVE-2025-4123MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire...
CVE-2025-4133MEDIUM5.4The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts whe...
CVE-2025-5062MEDIUM6.1The WooCommerce plugin for WordPress is vulnerable to PostMessage-Based Cross-Site Scripting via the 'customize-store' p...
CVE-2025-3885MEDIUM6.5Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows netwo...
CVE-2025-3480MEDIUM6.5MedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure Vulnerability. This vulnerability...
CVE-2025-48070MEDIUM4.3Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer tha...
CVE-2025-47942MEDIUM5.3The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxap...
CVE-2025-45755MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the S...
CVE-2025-5033MEDIUM5.3A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unk...
CVE-2025-5020MEDIUM4.3Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website...
CVE-2025-48069MEDIUM6.6ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `e...
CVE-2025-2102MEDIUM5.7Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Priv...
CVE-2025-4415MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now