2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-25939MEDIUM6.1Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey pa...
CVE-2025-27371MEDIUM6.9In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0 Client Authentication me...
CVE-2025-27370MEDIUM6.9OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations. When the private_key_jwt a...
CVE-2025-0686MEDIUM6.4A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses...
CVE-2025-0685MEDIUM6.4A flaw was found in grub2. When reading data from a jfs filesystem, grub's jfs filesystem module uses user-controlled pa...
CVE-2025-0684MEDIUM6.4A flaw was found in grub2. When performing a symlink lookup from a reiserfs filesystem, grub's reiserfs fs module uses u...
CVE-2025-27498MEDIUM5.6aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is t...
CVE-2025-25303MEDIUM6.9The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTransl...
CVE-2025-25302MEDIUM6.5Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is setup incorrectly. All ...
CVE-2025-0287MEDIUM5.1Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by...
CVE-2025-27420MEDIUM5.4WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scri...
CVE-2025-27418MEDIUM5.4WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scri...
CVE-2025-27417MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scri...
CVE-2025-27099MEDIUM4.8Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-sit...
CVE-2025-27094MEDIUM5.4Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user w...
CVE-2025-24023MEDIUM5.3Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users ...
CVE-2025-0555MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to ...
CVE-2025-27274MEDIUM4.9Path Traversal: '.../...//' vulnerability in axelkeller GPX Viewer gpx-viewer allows Path Traversal.This issue affects G...
CVE-2025-27273MEDIUM5.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in winking Affiliate ...
CVE-2025-26994MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaf...
CVE-2025-26989MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in softdiscover Zigaf...
CVE-2025-26984MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Al...
CVE-2025-26918MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology ...
CVE-2025-26917MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes WP Templ...
CVE-2025-25137MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Cross Site Request Forg...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now