2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13785MEDIUM6.5A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects so...
CVE-2025-13784MEDIUM4.8A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknow...
CVE-2025-66433MEDIUM4.2HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by subm...
CVE-2025-66432MEDIUM5In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.
CVE-2025-66424MEDIUM6.5Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40...
CVE-2025-66422MEDIUM4.3Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is ...
CVE-2025-66421MEDIUM5.4Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6....
CVE-2025-66420MEDIUM5.4Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and ...
CVE-2025-66291MEDIUM4.3OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment r...
CVE-2025-66290MEDIUM4.3OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitm...
CVE-2025-65892MEDIUM6.1Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execut...
CVE-2025-65540MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. ...
CVE-2025-66221MEDIUM5.3Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows p...
CVE-2025-61915MEDIUM6.7OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2....
CVE-2025-58436MEDIUM5.5OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2....
CVE-2025-53897MEDIUM6.8Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an...
CVE-2025-66036MEDIUM6.1Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cro...
CVE-2025-66027MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerabil...
CVE-2025-65113MEDIUM6.5ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerabi...
CVE-2025-64715MEDIUM5.5Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1....
CVE-2025-13683MEDIUM6.5Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affec...
CVE-2025-59792MEDIUM5.3Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks...
CVE-2025-59790MEDIUM5.4Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v...
CVE-2025-51736MEDIUM6.3File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-51734MEDIUM5.4Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now