2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62731MEDIUM4.8SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is...
CVE-2025-62729MEDIUM5.4SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML...
CVE-2025-62297MEDIUM5.4SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitr...
CVE-2025-62296MEDIUM5.4SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitra...
CVE-2025-62295MEDIUM5.4SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject ar...
CVE-2025-62293MEDIUM5.4SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Statu...
CVE-2025-60737MEDIUM6.1Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_0...
CVE-2025-36161MEDIUM5.9IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to ...
CVE-2025-65226MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.
CVE-2025-65223MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.
CVE-2025-65222MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.
CVE-2025-65221MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.
CVE-2025-65220MEDIUM4.3Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.
CVE-2025-64984MEDIUM6.1Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases pri...
CVE-2025-62346MEDIUM6.8A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's we...
CVE-2025-60799MEDIUM6.1phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The applicat...
CVE-2025-60798MEDIUM6.5phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes ...
CVE-2025-60797MEDIUM6.5phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application dire...
CVE-2025-60796MEDIUM6.1phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. Us...
CVE-2025-60794MEDIUM6.5Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit...
CVE-2025-5092MEDIUM6.4Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ligh...
CVE-2025-41076MEDIUM6.5In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed ses...
CVE-2025-40605MEDIUM5.3A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file...
CVE-2025-13469MEDIUM4.8A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unk...
CVE-2025-13450MEDIUM5.4A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /s...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now