2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65403MEDIUM6.5A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-63534MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component...
CVE-2025-63533MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php a...
CVE-2025-63095MEDIUM6.5Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows att...
CVE-2025-20085MEDIUM6.5A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. ...
CVE-2025-64030MEDIUM5.4Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via...
CVE-2025-63528MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinfo.php comp...
CVE-2025-63527MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php a...
CVE-2025-63526MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The ...
CVE-2025-63523MEDIUM6.5FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-o...
CVE-2025-63522MEDIUM4.6Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function
CVE-2025-63520MEDIUM6.1Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fu...
CVE-2025-13129MEDIUM4.3Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contr...
CVE-2025-49643MEDIUM6.5An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending sp...
CVE-2025-49642MEDIUM5.9Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directo...
CVE-2025-27232MEDIUM4.9An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver le...
CVE-2025-58408MEDIUM5.9Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data...
CVE-2025-13296MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Fo...
CVE-2025-8045MEDIUM4Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al...
CVE-2025-6349MEDIUM5.1Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al...
CVE-2025-41070MEDIUM4.8Reflected Cross-site Scripting (XSS) vulnerability in Sanoma's Clickedu. This vulnerability allows an attacker to execut...
CVE-2025-2879MEDIUM5.1Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd A...
CVE-2025-41739MEDIUM5.9An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the C...
CVE-2025-13819MEDIUM6.1Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to ...
CVE-2025-13809MEDIUM6.5A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this is...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now