2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-63716MEDIUM6.5The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unautho...
CVE-2025-63714MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute...
CVE-2025-63713MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary...
CVE-2025-57697MEDIUM6.5AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image...
CVE-2025-12829MEDIUM6.9An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data an...
CVE-2025-7719MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on...
CVE-2025-63785MEDIUM6.1A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2...
CVE-2025-63784MEDIUM6.5An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback...
CVE-2025-63687MEDIUM6.5An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/...
CVE-2025-63686MEDIUM6.5There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c938116...
CVE-2025-58465MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a us...
CVE-2025-58463MEDIUM4.9A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an admi...
CVE-2025-57712MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-57706MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user...
CVE-2025-54168MEDIUM4.8A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an admin...
CVE-2025-53413MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53412MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-53411MEDIUM4.9An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53410MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53409MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53408MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-52865MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-47207MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gain...
CVE-2025-46413MEDIUM5.3Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. W...
CVE-2025-10966MEDIUM4.3curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now