2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-31735MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in C. Johnson Footnot...
CVE-2025-31734MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Simple...
CVE-2025-31733MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boot Div WP Sitema...
CVE-2025-31732MEDIUM4.3Missing Authorization vulnerability in gb-plugins GB Gallery Slideshow gb-gallery-slideshow allows Exploiting Incorrectl...
CVE-2025-31731MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Philip John Author...
CVE-2025-31730MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DigitalCourt Marke...
CVE-2025-31121MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3....
CVE-2025-30676MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue...
CVE-2025-30354MEDIUM4.3Bruno is an open source IDE for exploring and testing APIs. A bug in the assertion runtime caused assert expressions to ...
CVE-2025-30224MEDIUM5.1MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors ...
CVE-2025-30210MEDIUM6.1Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components which intern...
CVE-2025-3035MEDIUM5.3By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab ...
CVE-2025-3031MEDIUM6.5An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed...
CVE-2025-3028MEDIUM6.5JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulner...
CVE-2025-31408MEDIUM4.3Missing Authorization vulnerability in Zoho Flow Zoho Flow zoho-flow allows Exploiting Incorrectly Configured Access Con...
CVE-2025-3084MEDIUM6.5When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This ca...
CVE-2025-30177MEDIUM6.5Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions. This issue affe...
CVE-2025-2906MEDIUM6.4The Contempo Real Estate Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versio...
CVE-2025-3082MEDIUM5.4A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different o...
CVE-2025-29868MEDIUM6.5Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: ...
CVE-2025-27427MEDIUM4.3A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue pe...
CVE-2025-1512MEDIUM6.4The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cro...
CVE-2025-1267MEDIUM5.5The Groundhogg plugin for Wordpress is vulnerable to Stored Cross-Site Scripting via the ‘label' parameter in versions u...
CVE-2025-31409MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Bridge Co...
CVE-2025-30926MEDIUM4.3Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons.This issue affects King Addo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now