2025 CVE Vulnerabilities

45,152 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-56380MEDIUM6.5Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the fra...
CVE-2025-56379MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execu...
CVE-2025-53881MEDIUM6.9A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalat...
CVE-2025-41010MEDIUM5.1Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) all...
CVE-2025-22862MEDIUM6.7An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2....
CVE-2025-11239MEDIUM4.3Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user'...
CVE-2025-0642MEDIUM6.3Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Softwa...
CVE-2025-54293MEDIUM6.5Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attacker...
CVE-2025-40992MEDIUM5.1Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/soc...
CVE-2025-40991MEDIUM5.4Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ...
CVE-2025-40990MEDIUM5.4Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ...
CVE-2025-40989MEDIUM5.4Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ...
CVE-2025-54468MEDIUM4.7A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an ex...
CVE-2025-54292MEDIUM4.6Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attac...
CVE-2025-54291MEDIUM5.3Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remo...
CVE-2025-54290MEDIUM5.3Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to d...
CVE-2025-54288MEDIUM6.8Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attack...
CVE-2025-54287MEDIUM6.5Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance co...
CVE-2025-40646MEDIUM5.4Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information a...
CVE-2025-61583MEDIUM6.1TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability h...
CVE-2025-61587MEDIUM6.1Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter o...
CVE-2025-59337MEDIUM6.8Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be...
CVE-2025-57389MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 all...
CVE-2025-61189MEDIUM6.3Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFil...
CVE-2025-61188MEDIUM6.3Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now