2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14013MEDIUM4.8A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.p...
CVE-2025-13488MEDIUM5.1Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded conten...
CVE-2025-9127MEDIUM5.5A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.
CVE-2025-66373MEDIUM4.8Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in...
CVE-2025-8074MEDIUM5.6Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users...
CVE-2025-65516MEDIUM6.1A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. ...
CVE-2025-63681MEDIUM4.3open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tas...
CVE-2025-61148MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authentic...
CVE-2025-40251MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_no...
CVE-2025-2848MEDIUM6.3A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, ...
CVE-2025-29845MEDIUM4.3A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
CVE-2025-29844MEDIUM4.3A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
CVE-2025-29843MEDIUM5.4A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
CVE-2025-14007MEDIUM6.1A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7...
CVE-2025-14006MEDIUM6.1A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown funct...
CVE-2025-14005MEDIUM6.1A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionali...
CVE-2025-11222MEDIUM6.1Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to u...
CVE-2025-41080MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attac...
CVE-2025-41079MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attac...
CVE-2025-14010MEDIUM5.5A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sen...
CVE-2025-12826MEDIUM4.8The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,...
CVE-2025-12782MEDIUM4.3The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2025-13513MEDIUM6.1The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` param...
CVE-2025-11379MEDIUM5.3The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and ...
CVE-2025-66411MEDIUM5.5Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now