2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7719MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on...
CVE-2025-63785MEDIUM6.1A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2...
CVE-2025-63784MEDIUM6.5An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback...
CVE-2025-63687MEDIUM6.5An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/...
CVE-2025-63686MEDIUM6.5There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c938116...
CVE-2025-58465MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a us...
CVE-2025-58463MEDIUM4.9A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an admi...
CVE-2025-57712MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-57706MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user...
CVE-2025-54168MEDIUM4.8A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an admin...
CVE-2025-53413MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53412MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-53411MEDIUM4.9An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53410MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53409MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53408MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-52865MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-47207MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gain...
CVE-2025-46413MEDIUM5.3Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. W...
CVE-2025-10966MEDIUM4.3curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host...
CVE-2025-64346MEDIUM6archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to fe...
CVE-2025-64339MEDIUM5.4ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature i...
CVE-2025-12527MEDIUM4.3The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capabili...
CVE-2025-12520MEDIUM4The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ...
CVE-2025-64336MEDIUM5.4ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is v...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now