2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-31935MEDIUM6.9Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data...
CVE-2025-31354MEDIUM5.3Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with cra...
CVE-2025-32427MEDIUM5.4Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or...
CVE-2025-32426MEDIUM5.4Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into t...
CVE-2025-3422MEDIUM6.3The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress...
CVE-2025-3421MEDIUM6.1The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is ...
CVE-2025-2575MEDIUM5.4The Z Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u...
CVE-2025-2541MEDIUM5.4The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2025-23387MEDIUM5.3A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users...
CVE-2025-2128MEDIUM6.5The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ parameter...
CVE-2025-32598MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Table Builder W...
CVE-2025-3512MEDIUM4.8There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted mar...
CVE-2025-1386MEDIUM4.9When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious externa...
CVE-2025-26335MEDIUM4.9Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent ...
CVE-2025-0125MEDIUM6.9An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar...
CVE-2025-0122MEDIUM5.1A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated atta...
CVE-2025-0121MEDIUM6.8A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-pri...
CVE-2025-32809MEDIUM5.4W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus ...
CVE-2025-32807MEDIUM5.3A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host...
CVE-2025-29918MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A ...
CVE-2025-29917MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Th...
CVE-2025-29916MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Da...
CVE-2025-22232MEDIUM5.3Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to...
CVE-2025-32027MEDIUM6.1Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenari...
CVE-2025-29150MEDIUM4.3BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now