2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22618MEDIUM5.4WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-...
CVE-2025-22617MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-22616MEDIUM5.4WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-...
CVE-2025-22615MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-22614MEDIUM5.4WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-...
CVE-2025-22613MEDIUM5.4WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-...
CVE-2025-22138MEDIUM5.1@codidact/qpixel is a Q&A-based community knowledge-sharing software. In affected versions when a category is set to pri...
CVE-2025-22134MEDIUM5.5When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer ...
CVE-2025-23027MEDIUM6.3next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.exam...
CVE-2025-23026MEDIUM6.1jte (Java Template Engine) is a secure and lightweight template engine for Java and Kotlin. In affected versions Jte HTM...
CVE-2025-22142MEDIUM5.4NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can a...
CVE-2025-22828MEDIUM4.3CloudStack users can add and read comments (annotations) on resources they are authorised to access.  Due to an access ...
CVE-2025-0404MEDIUM6.3A vulnerability has been found in liujianview gymxmjpa 1.0 and classified as critical. This vulnerability affects the fu...
CVE-2025-0403MEDIUM6.9A vulnerability, which was classified as problematic, has been found in 1902756969 reggie 1.0. Affected by this issue is...
CVE-2025-0401MEDIUM6.9A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the...
CVE-2025-0400MEDIUM5.4A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unkno...
CVE-2025-0398MEDIUM5.1A vulnerability has been found in longpi1 warehouse 1.0 and classified as problematic. Affected by this vulnerability is...
CVE-2025-0397MEDIUM5.3A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown functio...
CVE-2025-23109MEDIUM6.5Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This v...
CVE-2025-23108MEDIUM4.3Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofi...
CVE-2025-0106MEDIUM5.3A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate file...
CVE-2025-0104MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malic...
CVE-2025-23112MEDIUM6.1An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users t...
CVE-2025-23111MEDIUM6.1An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redire...
CVE-2025-23110MEDIUM6.1An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject fiel...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now