2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65657MEDIUM6.5FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1...
CVE-2025-65380MEDIUM6.5PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username...
CVE-2025-65379MEDIUM6.5PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically,...
CVE-2025-66468MEDIUM6.1The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior ...
CVE-2025-66460MEDIUM6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-66459MEDIUM6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-66458MEDIUM6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-66454MEDIUM6.5Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a har...
CVE-2025-57850MEDIUM6.4A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/p...
CVE-2025-13637MEDIUM4.3Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convince...
CVE-2025-13636MEDIUM4.3Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinc...
CVE-2025-13635MEDIUM4.4Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI...
CVE-2025-13634MEDIUM4.4Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to...
CVE-2025-13632MEDIUM5.4Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a use...
CVE-2025-65881MEDIUM6.1Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php.
CVE-2025-65215MEDIUM6.1Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product...
CVE-2025-65105MEDIUM5.3Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of th...
CVE-2025-64750MEDIUM4.5SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.3.5 and SingularityPRO 4....
CVE-2025-52622MEDIUM5.4The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the applicatio...
CVE-2025-65186MEDIUM6.1Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page con...
CVE-2025-64070MEDIUM5.4Sourcecodester Student Grades Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the Add New Subject ...
CVE-2025-65187MEDIUM6.1A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authentica...
CVE-2025-63872MEDIUM6.1DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated ...
CVE-2025-59704MEDIUM4.6Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the ...
CVE-2025-58113MEDIUM6.5An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.7.3.401...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now