2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65341MEDIUM6.1Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.
CVE-2025-51684MEDIUM6.1CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data ...
CVE-2025-36374MEDIUM5.5IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile...
CVE-2025-0152MEDIUM6.1IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1...
CVE-2025-36431MEDIUM5.4IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera...
CVE-2025-36298MEDIUM5.4IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0...
CVE-2025-65337MEDIUM6.1Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address ...
CVE-2025-59181MEDIUM4.8Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio...
CVE-2025-59180MEDIUM5.1Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm s...
CVE-2025-59178MEDIUM4.8Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera...
CVE-2025-59177MEDIUM6.8Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowi...
CVE-2025-9205MEDIUM6.4The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14....
CVE-2025-68081MEDIUM5.9Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
CVE-2025-50325MEDIUM5.4BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypa...
CVE-2025-13146MEDIUM6.5The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in a...
CVE-2025-68640MEDIUM5.3The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T...
CVE-2025-71397MEDIUM6.5SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi...
CVE-2025-71396MEDIUM6.5SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em...
CVE-2025-71395MEDIUM6.5SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to ...
CVE-2025-71394MEDIUM4.3SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows aut...
CVE-2025-71393MEDIUM6.5SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e...
CVE-2025-71391MEDIUM6.5SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated ...
CVE-2025-45870MEDIUM6.5LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet c...
CVE-2025-32781MEDIUM6.5Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior...
CVE-2025-62826MEDIUM4.3An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now