2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15121MEDIUM4.9A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the...
CVE-2025-15118MEDIUM4.3A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of th...
CVE-2025-15116MEDIUM4.8A security flaw has been discovered in OpenCart up to 4.1.0.3. Affected by this issue is some unknown functionality of t...
CVE-2025-68972MEDIUM4.7In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified...
CVE-2025-15106MEDIUM4.3A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi...
CVE-2025-15105MEDIUM5.9A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxu...
CVE-2025-68927MEDIUM6.1Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML in...
CVE-2025-68697MEDIUM5.4n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code ...
CVE-2025-61914MEDIUM5.4n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulner...
CVE-2025-66737MEDIUM4.3Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbi...
CVE-2025-67013MEDIUM6.5The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not impleme...
CVE-2025-67349MEDIUM6.1A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigatin...
CVE-2025-66947MEDIUM6.5SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editi...
CVE-2025-65885MEDIUM5.1An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8)...
CVE-2025-36230MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTM...
CVE-2025-36229MEDIUM4.3IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data du...
CVE-2025-14687MEDIUM6.5IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to...
CVE-2025-59888MEDIUM6.7Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution ...
CVE-2025-8075MEDIUM5.4Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-68946MEDIUM5.4In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
CVE-2025-52599MEDIUM6.5Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-68945MEDIUM5.3In Gitea before 1.21.2, an anonymous user can visit a private user's project.
CVE-2025-68944MEDIUM5.3Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package...
CVE-2025-68943MEDIUM5.3Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users...
CVE-2025-68942MEDIUM5.4Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now