2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4591MEDIUM6.4The Weluka Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'weluka-map' shortcod...
CVE-2025-4589MEDIUM6.4The Bon Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt-map' shortcode in...
CVE-2025-4126MEDIUM6.4The EG-Series plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [series] shortcode in a...
CVE-2025-47783MEDIUM6.1Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an at...
CVE-2025-46836MEDIUM6.6net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operatin...
CVE-2025-29691MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-29690MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-29689MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-29688MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-29686MEDIUM6.1A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scr...
CVE-2025-47888MEDIUM5.9Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for conne...
CVE-2025-47887MEDIUM4.3Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers wit...
CVE-2025-47886MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earl...
CVE-2025-44024MEDIUM6.1Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exist...
CVE-2025-25370MEDIUM4.6An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain...
CVE-2025-0137MEDIUM4.8An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar...
CVE-2025-0136MEDIUM5.3Using the AES-128-CCM algorithm for IPSec on certain Palo Alto Networks PAN-OS® firewalls (PA-7500, PA-5400, PA-5400f, P...
CVE-2025-0134MEDIUM6.5A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute a...
CVE-2025-0132MEDIUM6.9A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to dis...
CVE-2025-4664MEDIUM4.3Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cro...
CVE-2025-46786MEDIUM6.1Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network acc...
CVE-2025-46785MEDIUM6.5Buffer over-read in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service ...
CVE-2025-30668MEDIUM6.5Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network...
CVE-2025-30667MEDIUM6.5NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ...
CVE-2025-30666MEDIUM6.5NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now