2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30802MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPBean Our Team Members our-...
CVE-2025-30613MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N-Media Nmedia Mai...
CVE-2025-30594MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in samsk Include URL includ...
CVE-2025-2048MEDIUM4.1The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow...
CVE-2025-1986MEDIUM4.1The Gutentor WordPress plugin before 3.4.7 does not sanitize and escape a parameter before using it in a SQL statement,...
CVE-2025-1665MEDIUM5.4The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's...
CVE-2025-1534MEDIUM5.4CVE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Payara Pla...
CVE-2025-0418MEDIUM5.2Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local proje...
CVE-2025-3051MEDIUM6.5Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded si...
CVE-2025-30673MEDIUM6.5Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded sim...
CVE-2025-30672MEDIUM6.5Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to ...
CVE-2025-3043MEDIUM6.9A vulnerability, which was classified as critical, has been found in GuoMinJim PersonManage 1.0. This issue affects the ...
CVE-2025-3062MEDIUM6.6Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.
CVE-2025-3061MEDIUM6.6Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.
CVE-2025-3060MEDIUM6.6Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bo...
CVE-2025-3059MEDIUM5.3Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*.
CVE-2025-3037MEDIUM5.3A vulnerability has been found in yzk2356911358 StudentServlet-JSP cc0cdce25fbe43b6c58b60a77a2c85f52d2102f5/d4d7a0643f1d...
CVE-2025-31192MEDIUM6.7The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoi...
CVE-2025-31191MEDIUM5.5This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequo...
CVE-2025-31187MEDIUM5.5This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5...
CVE-2025-30470MEDIUM5.5A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia ...
CVE-2025-30467MEDIUM4.3The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoi...
CVE-2025-30463MEDIUM5.5The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 1...
CVE-2025-30455MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. A maliciou...
CVE-2025-30454MEDIUM5.5A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Seq...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now