2025 CVE Vulnerabilities

45,212 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-32485MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Cross Site Requ...
CVE-2025-32483MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Salisbury Re...
CVE-2025-31042MEDIUM5.3Missing Authorization vulnerability in rtakao Sandwich Adsense firsth3tagadsense allows Exploiting Incorrectly Configure...
CVE-2025-31035MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Chris WP ...
CVE-2025-31034MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AboZain Albanna Customize Login Page customize-login-page allows Cros...
CVE-2025-31020MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple ...
CVE-2025-31017MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Noakes Nav ...
CVE-2025-31012MEDIUM5.3Missing Authorization vulnerability in Phil Age Gate age-gate allows Accessing Functionality Not Properly Constrained by...
CVE-2025-31009MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in Jan Boddez IndieBlocks indieblocks allows Server Side Request Forger...
CVE-2025-31008MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Embeds For YouTube...
CVE-2025-31005MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts easyfonts allows Cross Site Request Forgery.This issu...
CVE-2025-31004MEDIUM4.3Missing Authorization vulnerability in Croover.inc Rich Table of Contents rich-table-of-content allows Exploiting Incorr...
CVE-2025-32381MEDIUM6.5XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to 0.1.18, Xgramma...
CVE-2025-32379MEDIUM6.1Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, passing untr...
CVE-2025-32378MEDIUM5.3Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-...
CVE-2025-32373MEDIUM6.5DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited...
CVE-2025-32371MEDIUM4.3DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url coul...
CVE-2025-32016MEDIUM4.7Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for i...
CVE-2025-29389MEDIUM6.1PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2.
CVE-2025-27391MEDIUM6.5Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker ...
CVE-2025-25023MEDIUM4.9IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privil...
CVE-2025-31672MEDIUM5.3Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, do...
CVE-2025-30677MEDIUM6.5Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connecto...
CVE-2025-2442MEDIUM6.8CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unau...
CVE-2025-2441MEDIUM4.6CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confiden...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now