2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-68607MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita ...
CVE-2025-68504MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSear...
CVE-2025-68503MEDIUM6.5Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-68502MEDIUM4.3Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorr...
CVE-2025-69205MEDIUM6.3Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and incl...
CVE-2025-15204MEDIUM4.8A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/m...
CVE-2025-69202MEDIUM6.5Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream servi...
CVE-2025-15203MEDIUM4.8A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/co...
CVE-2025-15202MEDIUM4.8A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src...
CVE-2025-14175MEDIUM6.5A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling ...
CVE-2025-15201MEDIUM5.4A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file...
CVE-2025-15200MEDIUM4.8A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. The affected element is the function getExceptionStatisti...
CVE-2025-14728MEDIUM6.8Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue clie...
CVE-2025-14280MEDIUM5.3The PixelYourSite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2025-55064MEDIUM4.8CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55063MEDIUM4.8CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55062MEDIUM4.8CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
CVE-2025-55060MEDIUM6.1CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVE-2025-68868MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Tex...
CVE-2025-53627MEDIUM5.3Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces as...
CVE-2025-69206MEDIUM4.3Hemmelig is a messing app with with client-side encryption and self-destructing messages. Prior to version 7.3.3, a Serv...
CVE-2025-68951MEDIUM6.1phpMyFAQ is an open source FAQ web application. Versions 4.0.14 and 4.0.15 have a stored cross-site scripting (XSS) vuln...
CVE-2025-68893MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in HETWORKS WordPress Image shrinker wp-image-shrinker allows Server Si...
CVE-2025-68928MEDIUM5.4Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could s...
CVE-2025-65442MEDIUM6.1DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrar...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now