2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30768MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mlaza jAlbum Bridg...
CVE-2025-30767MEDIUM5.4Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configu...
CVE-2025-30766MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy...
CVE-2025-30764MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool football-pool allows Cross Site Request Forger...
CVE-2025-30763MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP...
CVE-2025-29993MEDIUM5.3The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affecte...
CVE-2025-2685MEDIUM5.4The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-0273MEDIUM5.5HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be ...
CVE-2025-31165MEDIUM6.9Cross-Site Scripting (XSS) vulnerability in the Logbug module of NightWolf Penetration Testing Platform 1.2.2 allows att...
CVE-2025-2835MEDIUM5.3A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulner...
CVE-2025-2833MEDIUM6.9A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknow...
CVE-2025-2832MEDIUM5.3A vulnerability was found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 an...
CVE-2025-2481MEDIUM6.1The MediaView plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id' parameter in all version...
CVE-2025-20230MEDIUM6.5In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk S...
CVE-2025-30407MEDIUM6.3Local privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber P...
CVE-2025-2838MEDIUM6.5Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows n...
CVE-2025-20232MEDIUM5.7In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.103, 9.2.2...
CVE-2025-20231MEDIUM5.7In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk S...
CVE-2025-20228MEDIUM6.5In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.2.2403.108, and 9...
CVE-2025-20227MEDIUM4.3In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.10...
CVE-2025-20226MEDIUM5.7In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107...
CVE-2025-29322MEDIUM4.6A cross-site scripting (XSS) vulnerability in ScriptCase before v1.0.003 - Build 3 allows attackers to execute arbitrary...
CVE-2025-30352MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and p...
CVE-2025-30351MEDIUM4.3Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior t...
CVE-2025-2600MEDIUM6.8Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticate...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now