2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-66237MEDIUM6.7DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to...
CVE-2025-65959MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a St...
CVE-2025-65806MEDIUM4.3The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a ...
CVE-2025-63499MEDIUM6.1Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
CVE-2025-12996MEDIUM4.1Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext ...
CVE-2025-12994MEDIUM5.3Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an ...
CVE-2025-63361MEDIUM5.7Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00...
CVE-2025-59788MEDIUM5.4Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions bef...
CVE-2025-14013MEDIUM4.8A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.p...
CVE-2025-13488MEDIUM5.1Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded conten...
CVE-2025-9127MEDIUM5.5A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.
CVE-2025-66373MEDIUM4.8Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in...
CVE-2025-8074MEDIUM5.6Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users...
CVE-2025-65516MEDIUM6.1A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. ...
CVE-2025-63681MEDIUM4.3open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tas...
CVE-2025-61148MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authentic...
CVE-2025-40251MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_no...
CVE-2025-2848MEDIUM6.3A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, ...
CVE-2025-29845MEDIUM4.3A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
CVE-2025-29844MEDIUM4.3A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
CVE-2025-29843MEDIUM5.4A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
CVE-2025-14007MEDIUM6.1A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7...
CVE-2025-14006MEDIUM6.1A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown funct...
CVE-2025-14005MEDIUM6.1A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionali...
CVE-2025-11222MEDIUM6.1Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to u...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now