2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13807MEDIUM4.3A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the funct...
CVE-2025-13804MEDIUM4.3A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function...
CVE-2025-13802MEDIUM4.3A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted...
CVE-2025-13796MEDIUM6.3A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function...
CVE-2025-13793MEDIUM4.3A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affec...
CVE-2025-13791MEDIUM6.5A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org...
CVE-2025-13789MEDIUM5.3A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model...
CVE-2025-13785MEDIUM6.5A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects so...
CVE-2025-13784MEDIUM4.8A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknow...
CVE-2025-66433MEDIUM4.2HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by subm...
CVE-2025-66432MEDIUM5In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.
CVE-2025-66424MEDIUM6.5Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40...
CVE-2025-66422MEDIUM4.3Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is ...
CVE-2025-66421MEDIUM5.4Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6....
CVE-2025-66420MEDIUM5.4Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and ...
CVE-2025-66291MEDIUM4.3OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment r...
CVE-2025-66290MEDIUM4.3OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitm...
CVE-2025-65892MEDIUM6.1Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execut...
CVE-2025-65540MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. ...
CVE-2025-66221MEDIUM5.3Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows p...
CVE-2025-61915MEDIUM6.7OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2....
CVE-2025-58436MEDIUM5.5OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2....
CVE-2025-53897MEDIUM6.8Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an...
CVE-2025-66036MEDIUM6.1Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cro...
CVE-2025-66027MEDIUM6.5Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerabil...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now