2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-46225MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in pa...
CVE-2025-3518MEDIUM4.3It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabl...
CVE-2025-3814MEDIUM6.4The Tax Switch for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class-name’ pa...
CVE-2025-2839MEDIUM5.4The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ fu...
CVE-2025-2300MEDIUM5.5Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This is...
CVE-2025-3577MEDIUM4.9**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B f...
CVE-2025-1732MEDIUM6.7An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware vers...
CVE-2025-3855MEDIUM5.3A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by t...
CVE-2025-3849MEDIUM6.5A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects...
CVE-2025-2987MEDIUM5.4IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated...
CVE-2025-3843MEDIUM6.5A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown functi...
CVE-2025-32955MEDIUM6Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to befor...
CVE-2025-28103MEDIUM6.4Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
CVE-2025-28102MEDIUM6.1A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML...
CVE-2025-28099MEDIUM4.3opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,
CVE-2025-32793MEDIUM4Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1...
CVE-2025-28367MEDIUM6.5mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. A...
CVE-2025-28121MEDIUM6.1code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" p...
CVE-2025-3838MEDIUM6.1An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for inst...
CVE-2025-3837MEDIUM6.1An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is d...
CVE-2025-43970MEDIUM5.3An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by...
CVE-2025-43955MEDIUM6.8TwsCachedXPathAPI in Convertigo versions before 8.3.11 did not restrict commons-jxpath functions, which could allow expr...
CVE-2025-43954MEDIUM6.1QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.
CVE-2025-3826MEDIUM4.1A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management ...
CVE-2025-3825MEDIUM4.1A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Manage...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now