2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-39497MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro al...
CVE-2025-10933MEDIUM5.3An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads...
CVE-2025-65328MEDIUM6.5Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client I...
CVE-2025-66376MEDIUM6.1Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sh...
CVE-2025-68280MEDIUM6.5Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files ...
CVE-2025-12513MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-12511MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-68029MEDIUM6.3Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce wallet-system...
CVE-2025-68014MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in awethemes AweBooking awebooking allows Retrieve Embed...
CVE-2025-31046MEDIUM4.3Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Co...
CVE-2025-13056MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-12519MEDIUM5.3Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows...
CVE-2025-15237MEDIUM5.3QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat...
CVE-2025-15236MEDIUM5.3QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat...
CVE-2025-15022MEDIUM4.8Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS)...
CVE-2025-15455MEDIUM6.5A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/pa...
CVE-2025-15453MEDIUM6.3A security vulnerability has been detected in milvus up to 2.6.7. This vulnerability affects the function expr.Exec of t...
CVE-2025-15452MEDIUM4.8A weakness has been identified in xnx3 wangmarket up to 4.9. This affects the function variableList of the file /admin/s...
CVE-2025-15451MEDIUM4.8A security flaw has been discovered in xnx3 wangmarket up to 4.9. Affected by this issue is some unknown functionality o...
CVE-2025-15450MEDIUM6.3A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected by this v...
CVE-2025-5591MEDIUM5.4Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to...
CVE-2025-14830MEDIUM4.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JFrog Artif...
CVE-2025-3652MEDIUM6.9Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un...
CVE-2025-64122MEDIUM5.5Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoo...
CVE-2025-69417MEDIUM4.3In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share toke...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now