2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62411MEDIUM4.8LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site S...
CVE-2025-62407MEDIUM6.1Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through t...
CVE-2025-61923MEDIUM4.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and...
CVE-2025-61909MEDIUM4.4Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script ...
CVE-2025-61908MEDIUM6.5Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invali...
CVE-2025-61907MEDIUM6.5Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to th...
CVE-2025-61330MEDIUM6.5A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment...
CVE-2025-60641MEDIUM6.5The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexce...
CVE-2025-60639MEDIUM6.5Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).
CVE-2025-34512MEDIUM6.1Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in i...
CVE-2025-61789MEDIUM6.5Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with acce...
CVE-2025-58051MEDIUM6.5Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when impor...
CVE-2025-56700MEDIUM5.4Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allo...
CVE-2025-56699MEDIUM5.4SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows...
CVE-2025-53092MEDIUM6.5Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfigura...
CVE-2025-25298MEDIUM5.3Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum passwor...
CVE-2025-9559MEDIUM6.5Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inter...
CVE-2025-62493MEDIUM6.5A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect...
CVE-2025-62492MEDIUM6.5A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation o...
CVE-2025-55035MEDIUM6.1Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a se...
CVE-2025-11842MEDIUM6.3A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function ...
CVE-2025-11840MEDIUM5.5A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. E...
CVE-2025-61540MEDIUM6.5SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
CVE-2025-61539MEDIUM6.1Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.
CVE-2025-41254MEDIUM4.3STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized me...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now