2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-29914MEDIUM5.4OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.3.3, if a request is ma...
CVE-2025-29215MEDIUM6.5Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetContr...
CVE-2025-2565MEDIUM4.3The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through ...
CVE-2025-2552MEDIUM5.3A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been declared as problematic. This vulnerabil...
CVE-2025-2551MEDIUM5.3A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been classified as problematic. This affects ...
CVE-2025-2550MEDIUM5.3A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this issue...
CVE-2025-2547MEDIUM5.3A vulnerability, which was classified as problematic, has been found in D-Link DIR-618 and DIR-605L 2.02/3.02. This issu...
CVE-2025-2546MEDIUM5.3A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects...
CVE-2025-29412MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allow...
CVE-2025-29410MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attac...
CVE-2025-1496MEDIUM6.5Improper Restriction of Excessive Authentication Attempts vulnerability in BG-TEK Coslat Hotspot allows Password Brute F...
CVE-2025-0254MEDIUM5.9HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9...
CVE-2025-27888MEDIUM5.4Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page...
CVE-2025-1802MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘m...
CVE-2025-1474MEDIUM5.5In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerabil...
CVE-2025-0508MEDIUM5.9A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash c...
CVE-2025-0281MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. An attacker can...
CVE-2025-0192MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability exists in the latest version of wandb/openui. The vulnerability is pre...
CVE-2025-0191MEDIUM6.5A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914...
CVE-2025-0188MEDIUM6.5A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vu...
CVE-2025-0184MEDIUM6.5A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability o...
CVE-2025-0183MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic ...
CVE-2025-2108MEDIUM6.4The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2025-1766MEDIUM5.3The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized ...
CVE-2025-1314MEDIUM4.3The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request For...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now