2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48087MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlit...
CVE-2025-60360MEDIUM5.5radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.
CVE-2025-60359MEDIUM5.5radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
CVE-2025-11895MEDIUM4.3The Binary MLM Plan plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and includ...
CVE-2025-55099MEDIUM6.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-55098MEDIUM6.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-55097MEDIUM6.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-55096MEDIUM6.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-55093MEDIUM5.3In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...
CVE-2025-55092MEDIUM5.3In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a p...
CVE-2025-6894MEDIUM5.3An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou...
CVE-2025-61554MEDIUM5.5A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-0...
CVE-2025-60358MEDIUM5.5radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
CVE-2025-62418MEDIUM4.8Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a...
CVE-2025-62416MEDIUM6.8Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SS...
CVE-2025-62415MEDIUM4.8Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows a...
CVE-2025-62414MEDIUM4.8Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin...
CVE-2025-61514MEDIUM6.5An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitra...
CVE-2025-60855MEDIUM5.1Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows ...
CVE-2025-34255MEDIUM5.3D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic...
CVE-2025-34254MEDIUM5.3D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The applic...
CVE-2025-34253MEDIUM5.4D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to imp...
CVE-2025-11852MEDIUM5.5A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/...
CVE-2025-62413MEDIUM6.1MQTTX is an MQTT 5.0 desktop client and MQTT testing tool. A Cross-Site Scripting (XSS) vulnerability was introduced in ...
CVE-2025-62412MEDIUM4.8LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now