2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30092MEDIUM6.1Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allows XSS in multiple Velocity scripts.
CVE-2025-27776MEDIUM5.3Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and fil...
CVE-2025-27775MEDIUM5.3Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and fil...
CVE-2025-27774MEDIUM5.3Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and fil...
CVE-2025-26816MEDIUM6.5A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users...
CVE-2025-30258MEDIUM4.7In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid bac...
CVE-2025-27705MEDIUM5.5There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prio...
CVE-2025-2536MEDIUM6.1Cross-site scripting (XSS) vulnerability on Liferay Portal 7.4.3.82 through 7.4.3.128, and Liferay DXP 2024.Q3.0, 2024.Q...
CVE-2025-27704MEDIUM5.5There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prio...
CVE-2025-29925MEDIUM5.3XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when ...
CVE-2025-29405MEDIUM6.3An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows atta...
CVE-2025-29118MEDIUM6.5Tenda AC8 V16.03.34.06 was discovered to contain a stack overflow via the src parameter in the function sub_47D878.
CVE-2025-0431MEDIUM5.8Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send a...
CVE-2025-30196MEDIUM6.5Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the ...
CVE-2025-30152MEDIUM6.5The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2...
CVE-2025-30144MEDIUM6.5fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 5.0.6, the fast-jwt library does not properly valid...
CVE-2025-29770MEDIUM6.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of the...
CVE-2025-26486MEDIUM6Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash,...
CVE-2025-26485MEDIUM5.8A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts ...
CVE-2025-26475MEDIUM5.5Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances secu...
CVE-2025-23382MEDIUM5.8Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Infor...
CVE-2025-1472MEDIUM4.3Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker ...
CVE-2025-2511MEDIUM4.9The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions...
CVE-2025-27018MEDIUM6.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MyS...
CVE-2025-2290MEDIUM5.3The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to Unauthenticated Po...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now