2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-31101MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vault Group Pty Lt...
CVE-2025-31031MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Job Col...
CVE-2025-2888MEDIUM4.5During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when at...
CVE-2025-2887MEDIUM4.5During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to ...
CVE-2025-2886MEDIUM4.5Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even a...
CVE-2025-2885MEDIUM4.5Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to th...
CVE-2025-2878MEDIUM4.8A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerabi...
CVE-2025-22740MEDIUM5.3Missing Authorization vulnerability in Automattic Sensei LMS sensei-lms allows Exploiting Incorrectly Configured Access ...
CVE-2025-22739MEDIUM5.3Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access C...
CVE-2025-30366MEDIUM5.4WeGIA is a Web manager for charitable institutions. Versions prior to 3.2.8 are vulnerable to stored cross-site scriptin...
CVE-2025-30363MEDIUM5.4WeGIA is a Web manager for charitable institutions. A stored Cross-Site Scripting (XSS) vulnerability was identified in ...
CVE-2025-30362MEDIUM5.4WeGIA is a Web manager for charitable institutions. A stored Cross-Site Scripting (XSS) vulnerability was identified in ...
CVE-2025-26762MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooComm...
CVE-2025-26265MEDIUM6.5A segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE C...
CVE-2025-22640MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in integrationdevpayt...
CVE-2025-22638MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in acowebs Product Ta...
CVE-2025-22637MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in verkkovaraani Print PDF Generator and Publisher nopeamedia allows Cro...
CVE-2025-22634MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in MD Abu Jubayer Hossain Easy Booked – Appointment Booking and Scheduli...
CVE-2025-22629MEDIUM5.3Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Accessing Functionality Not Properly Constrai...
CVE-2025-22497MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bramwaas Simple Go...
CVE-2025-22496MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MarMar8x Notif Bel...
CVE-2025-22278MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes Whiti...
CVE-2025-31181MEDIUM6.2A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.
CVE-2025-31180MEDIUM6.2A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.
CVE-2025-31179MEDIUM6.2A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now