2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10947MEDIUM5.5A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of...
CVE-2025-10946MEDIUM5.1A vulnerability was detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. The affected element is a...
CVE-2025-10945MEDIUM5.1A security vulnerability has been detected in nuz007 smsboom up to 01b2f35bbbc23f3e0f60f38ca0e3d1b286f8d674. Impacted is...
CVE-2025-10944MEDIUM5.1A weakness has been identified in yi-ge get-header-ip up to 589b23d0eb0043c310a6a13ce4bbe2505d0d0b15. This issue affects...
CVE-2025-10943MEDIUM5.1A security flaw has been discovered in MikeCen WeChat-Face-Recognition up to 6e3f72bf8547d80b59e330f1137e4aa505f492c1. T...
CVE-2025-10940MEDIUM4.8A vulnerability was found in Total.js CMS 1.0.0. Affected by this vulnerability is the function layouts_save of the file...
CVE-2025-21056MEDIUM6.6Improper input validation in Retail Mode prior to version 5.59.4 allows self attackers to execute privileged commands on...
CVE-2025-57324MEDIUM6.5parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateContr...
CVE-2025-57320MEDIUM6.5json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setDa...
CVE-2025-59824MEDIUM5.4Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLi...
CVE-2025-59525MEDIUM6.1Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization...
CVE-2025-57351MEDIUM6.5A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation...
CVE-2025-57348MEDIUM6.5The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initializatio...
CVE-2025-55178MEDIUM5.3Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could pote...
CVE-2025-59524MEDIUM6.1Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow ...
CVE-2025-57354MEDIUM6.5A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user...
CVE-2025-57353MEDIUM5.3The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Du...
CVE-2025-57352MEDIUM5.3A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespa...
CVE-2025-48867MEDIUM4.8Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerabi...
CVE-2025-20338MEDIUM6.7A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri...
CVE-2025-20316MEDIUM5.3A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X...
CVE-2025-20314MEDIUM6.7A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an una...
CVE-2025-20313MEDIUM6.7Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileg...
CVE-2025-20293MEDIUM5.3A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for ...
CVE-2025-20240MEDIUM6.1A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attack...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now