2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-66305MEDIUM4.9Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the...
CVE-2025-66303MEDIUM4.9Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified i...
CVE-2025-66302MEDIUM6.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CM...
CVE-2025-65622MEDIUM5.4Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user ...
CVE-2025-65621MEDIUM5.4Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes...
CVE-2025-58044MEDIUM6.1JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and ...
CVE-2025-63317MEDIUM5.4Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization ap...
CVE-2025-12756MEDIUM4.3Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user pe...
CVE-2025-65407MEDIUM6.5A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows atta...
CVE-2025-11772MEDIUM6.6A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code w...
CVE-2025-13837MEDIUM5.5When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file...
CVE-2025-13835MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc...
CVE-2025-13653MEDIUM4.3In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which ...
CVE-2025-65408MEDIUM6.5A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming M...
CVE-2025-65406MEDIUM6.5A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allow...
CVE-2025-65405MEDIUM6.5A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows ...
CVE-2025-65404MEDIUM6.5A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Deni...
CVE-2025-65403MEDIUM6.5A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-63534MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component...
CVE-2025-63533MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php a...
CVE-2025-63095MEDIUM6.5Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows att...
CVE-2025-20085MEDIUM6.5A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. ...
CVE-2025-64030MEDIUM5.4Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via...
CVE-2025-63528MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php comp...
CVE-2025-63527MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now