2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2849MEDIUM5.5A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxEl...
CVE-2025-27793MEDIUM5.3Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2025-26738MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Graham Quick Inter...
CVE-2025-26737MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes City ...
CVE-2025-26736MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in victortihai Mornin...
CVE-2025-26734MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in peregrinethemes He...
CVE-2025-26732MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware Sto...
CVE-2025-26731MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ...
CVE-2025-26619MEDIUM6.1Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2025-22816MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetrendy Power M...
CVE-2025-22770MEDIUM5.4Missing Authorization vulnerability in EnvoThemes Envo Multipurpose allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-22673MEDIUM4.3Missing Authorization vulnerability in WPFactory EAN for WooCommerce ean-for-woocommerce allows Exploiting Incorrectly C...
CVE-2025-22672MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-u...
CVE-2025-21871MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix supplicant wait loop OP-TEE suppli...
CVE-2025-21870MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Harden loops for looking ...
CVE-2025-21868MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SK...
CVE-2025-2255MEDIUM5.4An issue has been discovered in Gitlab EE/CE for AppSec affecting all versions from 13.5.0 before 17.8.6, 17.9 before 17...
CVE-2025-0811MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17....
CVE-2025-31140MEDIUM6.1In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
CVE-2025-31139MEDIUM6.5In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log
CVE-2025-30925MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webangon The Pack ...
CVE-2025-30923MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in powerfulwp Gift Message for WooCommerce gift-message-for-woocommerce ...
CVE-2025-30922MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simplebooklet Simp...
CVE-2025-30920MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in teastudio.pl WP Po...
CVE-2025-30918MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme Struc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now