2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61554MEDIUM5.5A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-0...
CVE-2025-60358MEDIUM5.5radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
CVE-2025-62418MEDIUM4.8Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a...
CVE-2025-62416MEDIUM6.8Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SS...
CVE-2025-62415MEDIUM4.8Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a...
CVE-2025-62414MEDIUM4.8Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin...
CVE-2025-61514MEDIUM6.5An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitra...
CVE-2025-60855MEDIUM5.1Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows ...
CVE-2025-34255MEDIUM5.3D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic...
CVE-2025-34254MEDIUM5.3D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic...
CVE-2025-34253MEDIUM5.4D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to imp...
CVE-2025-11852MEDIUM5.5A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/...
CVE-2025-62413MEDIUM6.1MQTTX is an MQTT 5.0 desktop client and MQTT testing tool. A Cross-Site Scripting (XSS) vulnerability was introduced in ...
CVE-2025-62412MEDIUM4.8LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules p...
CVE-2025-62411MEDIUM4.8LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site S...
CVE-2025-62407MEDIUM6.1Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through t...
CVE-2025-61923MEDIUM4.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and...
CVE-2025-61909MEDIUM4.4Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script ...
CVE-2025-61908MEDIUM6.5Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invali...
CVE-2025-61907MEDIUM6.5Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to th...
CVE-2025-61330MEDIUM6.5A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment...
CVE-2025-60641MEDIUM6.5The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexce...
CVE-2025-60639MEDIUM6.5Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).
CVE-2025-34512MEDIUM6.1Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in i...
CVE-2025-61789MEDIUM6.5Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with acce...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now