2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-21401MEDIUM4.5Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2025-25304MEDIUM6.9Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2025-25296MEDIUM6.1Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` en...
CVE-2025-25290MEDIUM5.3@octokit/request sends parameterized requests to GitHub’s APIs with sensible defaults in browsers and Node. Starting in ...
CVE-2025-25289MEDIUM5.3@octokit/request-error is an error class for Octokit request errors. Starting in version 1.0.0 and prior to version 6.1....
CVE-2025-25288MEDIUM5.3@octokit/plugin-paginate-rest is the Octokit plugin to paginate REST API endpoint responses. For versions starting in 1....
CVE-2025-25285MEDIUM5.3@octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version ...
CVE-2025-0503MEDIUM5.3Mattermost versions 9.11.x <= 9.11.6 fail to filter out DMs from the deleted channels endpoint which allows an attacker ...
CVE-2025-26158MEDIUM5.6A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Att...
CVE-2025-26157MEDIUM5.9A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V...
CVE-2025-25993MEDIUM5.1SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the para...
CVE-2025-25992MEDIUM5.1SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_...
CVE-2025-25991MEDIUM5.1SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /instal...
CVE-2025-25990MEDIUM6.1Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the ...
CVE-2025-25988MEDIUM4.8Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custo...
CVE-2025-25204MEDIUM6.3`gh` is GitHub’s official command line tool. Starting in version 2.49.0 and prior to version 2.67.0, under certain condi...
CVE-2025-25740MEDIUM5.5D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the PSK parameter ...
CVE-2025-1239MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi...
CVE-2025-1071MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi...
CVE-2025-0178MEDIUM6.1An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulat...
CVE-2025-24700MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WP Ev...
CVE-2025-24567MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Emb...
CVE-2025-23857MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SmartDataSoft Esse...
CVE-2025-23771MEDIUM6.5Missing Authorization vulnerability in Murali Push Notification for Post and BuddyPress push-notification-for-post-and-b...
CVE-2025-23766MEDIUM6.5Missing Authorization vulnerability in ashamil OPSI Israel Domestic Shipments woo-ups-pickup allows Exploiting Incorrect...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now