2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62675MEDIUM4.3An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera...
CVE-2025-43892MEDIUM4.3A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all v...
CVE-2025-15665MEDIUM5.4The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Sl...
CVE-2025-5017MEDIUM4.9The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’...
CVE-2025-13968MEDIUM6.4The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod...
CVE-2025-30008MEDIUM5.4HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users...
CVE-2025-11977MEDIUM6.6The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin fo...
CVE-2025-12506MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and ...
CVE-2025-14785MEDIUM6.4The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor...
CVE-2025-12799MEDIUM6.5A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined config...
CVE-2025-8591MEDIUM6.1The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back ...
CVE-2025-71385MEDIUM6.1Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoi...
CVE-2025-69132MEDIUM6.5Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
CVE-2025-66076MEDIUM5.3Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
CVE-2025-15666MEDIUM5.3A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerabili...
CVE-2025-71381MEDIUM6.9Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the midd...
CVE-2025-36359MEDIUM6.5IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow...
CVE-2025-36336MEDIUM5.9IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to ob...
CVE-2025-36333MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actio...
CVE-2025-36328MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow a remote attacker to obtain sensitive information w...
CVE-2025-36327MEDIUM6.5IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls a...
CVE-2025-36324MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 s vulnerable to server-side request forgery (SSRF). This may al...
CVE-2025-36323MEDIUM5.4IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allow...
CVE-2025-36321MEDIUM5.7IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject...
CVE-2025-36320MEDIUM6.4IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerabilit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now