2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59754MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59753MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59752MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59751MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59750MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59749MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59748MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59747MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-59746MEDIUM6.1Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e...
CVE-2025-57443MEDIUM5.1FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library...
CVE-2025-56381MEDIUM6.5ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportv...
CVE-2025-56380MEDIUM6.5Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the fra...
CVE-2025-56379MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execu...
CVE-2025-53881MEDIUM6.9A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalat...
CVE-2025-41010MEDIUM5.1Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) all...
CVE-2025-22862MEDIUM6.7An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2....
CVE-2025-11239MEDIUM4.3Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user'...
CVE-2025-0642MEDIUM6.3Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Softwa...
CVE-2025-54293MEDIUM6.5Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attacker...
CVE-2025-40992MEDIUM5.1Stored XSS vulnerability in Creativeitem Sociopro due to lack of proper validation of user inputs via the endpoint '/soc...
CVE-2025-40991MEDIUM5.4Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ...
CVE-2025-40990MEDIUM5.4Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ...
CVE-2025-40989MEDIUM5.4Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user ...
CVE-2025-54468MEDIUM4.7A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an ex...
CVE-2025-54292MEDIUM4.6Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attac...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now