2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1076MEDIUM4.8A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability co...
CVE-2025-1074MEDIUM5.3A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout...
CVE-2025-0859MEDIUM6.5The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal...
CVE-2025-24845MEDIUM5.5Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home...
CVE-2025-24483MEDIUM5.5NULL pointer dereference vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker ...
CVE-2025-0522MEDIUM4.7The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well ...
CVE-2025-0799MEDIUM6.5IBM App Connect enterprise 12.0.1.0 through 12.0.12.10 and 13.0.1.0 through 13.0.2.1 could allow an authenticated user t...
CVE-2025-24805MEDIUM5.5Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malw...
CVE-2025-24804MEDIUM4.3Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malw...
CVE-2025-24803MEDIUM5.4Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malw...
CVE-2025-24319MEDIUM6.5When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the B...
CVE-2025-23419MEDIUM5.3When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption...
CVE-2025-23413MEDIUM6.7When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive inf...
CVE-2025-20207MEDIUM4.3A vulnerability in Simple Network Management Protocol (SNMP) polling for Cisco Secure Email and Web Manager, Cisco Secur...
CVE-2025-20205MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals cou...
CVE-2025-20204MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals cou...
CVE-2025-20185MEDIUM6.7A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Emai...
CVE-2025-20183MEDIUM5.3A vulnerability in a policy-based Cisco Application Visibility and Control (AVC) implementation of Cisco AsyncOS Softwar...
CVE-2025-20180MEDIUM4.8A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager a...
CVE-2025-20179MEDIUM6.1A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote ...
CVE-2025-0858MEDIUM5.8A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does n...
CVE-2025-21117MEDIUM5.5Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local atta...
CVE-2025-22602MEDIUM6.1Discourse is an open source platform for community discussion. In affected versions an attacker can execute arbitrary Ja...
CVE-2025-24967MEDIUM5.4reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability...
CVE-2025-24966MEDIUM5.4reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application imprope...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now