2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-70037MEDIUM6.1An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This a...
CVE-2025-70060MEDIUM5.4An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v...
CVE-2025-70050MEDIUM6.5An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 wh...
CVE-2025-70040MEDIUM5.3An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-...
CVE-2025-69648MEDIUM6.2GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor...
CVE-2025-69647MEDIUM6.2GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor...
CVE-2025-40638MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot. This vulnerability allows an attacker...
CVE-2025-41763MEDIUM6.5A low‑privileged remote attacker can directly interact with the wwwdnload.cgi endpoint to download any resource availabl...
CVE-2025-41762MEDIUM6.2An unauthenticated attacker can abuse the weak hash of the backup generated by the wwwdnload.cgi endpoint to gain unauth...
CVE-2025-41760MEDIUM4.9An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an ...
CVE-2025-41759MEDIUM4.9An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these...
CVE-2025-41755MEDIUM6.5A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system....
CVE-2025-41754MEDIUM6.5A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpo...
CVE-2025-69653MEDIUM6.5A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbb...
CVE-2025-69652MEDIUM6.2GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF b...
CVE-2025-69651MEDIUM5.5GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ...
CVE-2025-69646MEDIUM5.5Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_...
CVE-2025-69645MEDIUM5.5Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug ...
CVE-2025-69644MEDIUM5An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing ...
CVE-2025-59544MEDIUM4.3Chamilo is a learning management system. Prior to version 1.11.34, the functionality for the user to update the category...
CVE-2025-59540MEDIUM5.4Chamilo is a learning management system. Prior to version 1.11.34, a stored XSS vulnerability exists in Chamilo LMS that...
CVE-2025-30413MEDIUM4.4Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber...
CVE-2025-11790MEDIUM4.4Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber...
CVE-2025-7375MEDIUM6.5A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can...
CVE-2025-64166MEDIUM5.4Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability w...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now