2025 CVE Vulnerabilities

45,328 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-40649MEDIUM5.1Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infras...
CVE-2025-3718MEDIUM5.4A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing valid...
CVE-2025-11390MEDIUM6.1A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-11360MEDIUM5.3A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the ...
CVE-2025-10645MEDIUM5.3The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, ...
CVE-2025-7400MEDIUM6.4The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featur...
CVE-2025-61768MEDIUM5.1KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Fo...
CVE-2025-43824MEDIUM5.4The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 ...
CVE-2025-59452MEDIUM5.8The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an...
CVE-2025-59450MEDIUM4.3The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network a...
CVE-2025-59449MEDIUM4.9The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-ac...
CVE-2025-59448MEDIUM4.7Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet...
CVE-2025-56382MEDIUM6.1A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4...
CVE-2025-28129MEDIUM5.4Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.
CVE-2025-61769MEDIUM6.1Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including...
CVE-2025-61766MEDIUM6.5Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recu...
CVE-2025-60969MEDIUM5.7Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00...
CVE-2025-60961MEDIUM6.1Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 V...
CVE-2025-0038MEDIUM6.6In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firm...
CVE-2025-61765MEDIUM6.4python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerab...
CVE-2025-61224MEDIUM6.5Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra...
CVE-2025-61198MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Opt...
CVE-2025-11337MEDIUM5.5A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown...
CVE-2025-11336MEDIUM5.5A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected ...
CVE-2025-11332MEDIUM6.1A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now