2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-3609MEDIUM5.3The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and inclu...
CVE-2025-4305MEDIUM6.3A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the f...
CVE-2025-4293MEDIUM5.4A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functiona...
CVE-2025-4292MEDIUM5.4A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknow...
CVE-2025-1493MEDIUM5.3IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticat...
CVE-2025-1000MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 coul...
CVE-2025-0915MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 un...
CVE-2025-4287MEDIUM4.8A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the functi...
CVE-2025-4286MEDIUM4.9A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an un...
CVE-2025-46734MEDIUM6.4league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of th...
CVE-2025-46730MEDIUM6.5MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-...
CVE-2025-45618MEDIUM6.5Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE all...
CVE-2025-46720MEDIUM4.3Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can b...
CVE-2025-46719MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6....
CVE-2025-46571MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6....
CVE-2025-46553MEDIUM6.1@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1...
CVE-2025-46340MEDIUM5.4Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, du...
CVE-2025-46335MEDIUM5.4Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mo...
CVE-2025-29573MEDIUM6.1Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms mo...
CVE-2025-4051MEDIUM6.3Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced...
CVE-2025-45239MEDIUM5.3An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.
CVE-2025-45236MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to exe...
CVE-2025-45240MEDIUM6.5foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.
CVE-2025-43915MEDIUM6.5In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, ...
CVE-2025-1992MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now