2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-24578MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader El...
CVE-2025-24575MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HelloAsso HelloAss...
CVE-2025-24573MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softaculous PageLa...
CVE-2025-24572MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Re...
CVE-2025-24571MEDIUM5.4Missing Authorization vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Exploiting Incorrectly Co...
CVE-2025-24568MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates astra-sites allows Cross Site Requ...
CVE-2025-24552MEDIUM5.3Generation of Error Message Containing Sensitive Information vulnerability in paytiumsupport Paytium paytium allows Retr...
CVE-2025-24547MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matthias.wagner Ca...
CVE-2025-24546MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allow...
CVE-2025-24543MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allow...
CVE-2025-24542MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram ic...
CVE-2025-24025MEDIUM6.1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-22610MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-22608MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-23991MEDIUM4.3Missing Authorization vulnerability in Dotstore Product Size Charts Plugin for WooCommerce woo-advanced-product-size-cha...
CVE-2025-22607MEDIUM5.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0...
CVE-2025-0697MEDIUM6.9A vulnerability, which was classified as problematic, was found in Telstra Smart Modem Gen 2 up to 20250115. This affect...
CVE-2025-0314MEDIUM6.1An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.6.4, 17.7 before 17.7.3, and 17....
CVE-2025-0693MEDIUM6.9Variable response times in the AWS Sign-in IAM user login flow allowed for the use of brute force enumeration techniques...
CVE-2025-24353MEDIUM4.3Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.2.0, when sharing a...
CVE-2025-23227MEDIUM5.4IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scriptin...
CVE-2025-0648MEDIUM4.9Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highl...
CVE-2025-0619MEDIUM4.9Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover ext...
CVE-2025-24530MEDIUM6.4An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables fe...
CVE-2025-24529MEDIUM6.4An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now