2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62397MEDIUM5.3The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially ...
CVE-2025-62396MEDIUM5.3An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings ...
CVE-2025-62395MEDIUM4.3A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information fr...
CVE-2025-62394MEDIUM4.3Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive u...
CVE-2025-62393MEDIUM4.3A flaw was found in the course overview output function where user access permissions were not fully enforced. This coul...
CVE-2025-10355MEDIUM5.1Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious UR...
CVE-2025-41073MEDIUM6.5Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated atta...
CVE-2025-40643MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du...
CVE-2025-9981MEDIUM4.8QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with adm...
CVE-2025-9980MEDIUM4.8QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin p...
CVE-2025-10727MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner S...
CVE-2025-62499MEDIUM4.8Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted in...
CVE-2025-54856MEDIUM4.8Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored b...
CVE-2025-54806MEDIUM6.1GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a...
CVE-2025-62820MEDIUM4.9Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within t...
CVE-2025-48430MEDIUM5.5Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Comm...
CVE-2025-48428MEDIUM6.7Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated us...
CVE-2025-41402MEDIUM5.5Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to e...
CVE-2025-35981MEDIUM5.5Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privil...
CVE-2025-62710MEDIUM5.9Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initial...
CVE-2025-62706MEDIUM6.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF...
CVE-2025-62705MEDIUM4.9OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not ...
CVE-2025-62613MEDIUM6.9VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to b...
CVE-2025-62612MEDIUM5.3FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link i...
CVE-2025-62247MEDIUM6.5Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 20...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now