2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61457MEDIUM6.1code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php.
CVE-2025-61255MEDIUM6.1Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search pa...
CVE-2025-56802MEDIUM5.1The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files...
CVE-2025-56801MEDIUM5.1The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB ...
CVE-2025-56800MEDIUM5.1Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application impl...
CVE-2025-56799MEDIUM6.5Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism...
CVE-2025-8050MEDIUM6.5External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal.  The vulnerability could...
CVE-2025-60790MEDIUM6.5ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is ...
CVE-2025-60427MEDIUM6.5LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can ...
CVE-2025-12031MEDIUM5.3HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the ...
CVE-2025-62763MEDIUM5Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.
CVE-2025-62605MEDIUM4.3Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifia...
CVE-2025-62598MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ...
CVE-2025-62597MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, ...
CVE-2025-62595MEDIUM6.1Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to ...
CVE-2025-60511MEDIUM4.3Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability...
CVE-2025-60506MEDIUM5.4Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An ...
CVE-2025-62250MEDIUM6.5Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023....
CVE-2025-61194MEDIUM6.5daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.
CVE-2025-61181MEDIUM6.5daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.
CVE-2025-60280MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code ...
CVE-2025-60934MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Perfor...
CVE-2025-60933MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Perf...
CVE-2025-60932MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Per...
CVE-2025-59438MEDIUM5.3Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now