2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-26695MEDIUM5.3When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have l...
CVE-2025-1296MEDIUM6.5Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token a...
CVE-2025-26910MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects ...
CVE-2025-25620MEDIUM5.4Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.
CVE-2025-25616MEDIUM4.3Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The aff...
CVE-2025-1944MEDIUM6.5picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to e...
CVE-2025-24387MEDIUM6.5A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie sett...
CVE-2025-27257MEDIUM6.1Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated...
CVE-2025-27253MEDIUM6.1A CWE-15 "External Control of System or Configuration Setting" in GE Vernova UR IED family devices from version 7.0 up t...
CVE-2025-2150MEDIUM5.4The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular pri...
CVE-2025-1926MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2025-2133MEDIUM4.8A vulnerability classified as problematic was found in ftcms 2.1. Affected by this vulnerability is an unknown functiona...
CVE-2025-2131MEDIUM4.8A vulnerability was found in dayrui XunRuiCMS up to 4.6.3. It has been rated as problematic. This issue affects some unk...
CVE-2025-2130MEDIUM5.4A vulnerability was found in OpenXE up to 1.12. It has been declared as problematic. This vulnerability affects unknown ...
CVE-2025-2129MEDIUM6.3A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The ma...
CVE-2025-2127MEDIUM6.1A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected i...
CVE-2025-2125MEDIUM4.3A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects u...
CVE-2025-2124MEDIUM5.1A vulnerability, which was classified as problematic, was found in Control iD RH iD 25.2.25.0. This affects an unknown p...
CVE-2025-2123MEDIUM6.1A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is t...
CVE-2025-2122MEDIUM5.3A vulnerability classified as problematic was found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected by this v...
CVE-2025-27636MEDIUM5.6Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel:...
CVE-2025-2120MEDIUM4.6A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been rated as problematic. This issue...
CVE-2025-2117MEDIUM6.3A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and...
CVE-2025-2116MEDIUM5.3A vulnerability has been found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3....
CVE-2025-1382MEDIUM6.1The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing saniti...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now