2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-0814MEDIUM6.9CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services runnin...
CVE-2025-0661MEDIUM4.3The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu...
CVE-2025-0837MEDIUM5.4The Puzzles theme for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and inclu...
CVE-2025-1198MEDIUM5.3An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 pr...
CVE-2025-20097MEDIUM5.3Uncaught exception in OpenBMC Firmware for the Intel(R) Server M50FCP Family and Intel(R) Server D50DNP Family before ve...
CVE-2025-1229MEDIUM6.3A vulnerability classified as critical was found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378ddd6. Af...
CVE-2025-1228MEDIUM5.3A vulnerability classified as problematic has been found in olajowon Loggrove up to e428fac38cc480f011afcb1d8ce6c2bad378...
CVE-2025-0113MEDIUM5.3A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthori...
CVE-2025-0111MEDIUM6.5An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker wit...
CVE-2025-0109MEDIUM6.9An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unau...
CVE-2025-1225MEDIUM6.3A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the fu...
CVE-2025-25201MEDIUM4Nitrokey 3 Firmware is the the firmware of Nitrokey 3 USB keys. For release 1.8.0, and test releases with PIV enabled pr...
CVE-2025-25741MEDIUM5.4D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the IPv6_PppoePass...
CVE-2025-1213MEDIUM5.4A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some un...
CVE-2025-25184MEDIUM6.5Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::...
CVE-2025-1209MEDIUM5.4A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function se...
CVE-2025-1208MEDIUM5.4A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as problematic. This issue affects some ...
CVE-2025-0556MEDIUM6.5In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework impleme...
CVE-2025-0516MEDIUM4.3Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow user...
CVE-2025-1202MEDIUM6.5A vulnerability classified as critical has been found in SourceCodester Best Church Management Software 1.1. Affected is...
CVE-2025-0376MEDIUM6.1An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 1...
CVE-2025-26376MEDIUM6.5A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 ...
CVE-2025-26374MEDIUM4.3A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal t...
CVE-2025-26373MEDIUM6.5A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to...
CVE-2025-26367MEDIUM4.3A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now