2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20194MEDIUM5.4A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privile...
CVE-2025-20193MEDIUM6.5A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privile...
CVE-2025-20190MEDIUM6.5A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authen...
CVE-2025-20187MEDIUM6.5A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could...
CVE-2025-20181MEDIUM6.8A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow a...
CVE-2025-20157MEDIUM5.9A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, co...
CVE-2025-20155MEDIUM6A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write ...
CVE-2025-20151MEDIUM4.3A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS ...
CVE-2025-20147MEDIUM5.4A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c...
CVE-2025-20137MEDIUM4.7A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 100...
CVE-2025-46827MEDIUM5.4Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtai...
CVE-2025-47692MEDIUM4.3Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configure...
CVE-2025-47691MEDIUM5.5Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-memb...
CVE-2025-47686MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DELUCKS DELUCKS SE...
CVE-2025-47684MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Smaily Smaily for WP smaily-for-wp allows Cross Site Request Forgery....
CVE-2025-47681MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Ability, Inc Web Accessibility with Max Access accessibility-toolbar ...
CVE-2025-47679MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RS WP THEMES RS WP...
CVE-2025-47677MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga...
CVE-2025-47676MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faiyaz Alam User L...
CVE-2025-47675MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woobox Woobox woob...
CVE-2025-47674MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Credova Financial Credova_Financial credova-financial allows Cross Si...
CVE-2025-47669MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sabuj Kundu CBX Ma...
CVE-2025-47668MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cookiecode CookieC...
CVE-2025-47667MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent liveagent allows Cross Site Request Forgery.This ...
CVE-2025-47665MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bistromatic N360 |...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now