2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58354MEDIUM6.9Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2025-56311MEDIUM6.5In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authentic...
CVE-2025-59825MEDIUM6.1astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-...
CVE-2025-57636MEDIUM6.5OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injecti...
CVE-2025-58674MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows S...
CVE-2025-56146MEDIUM5.3Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.
CVE-2025-45326MEDIUM6.5An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.p...
CVE-2025-59821MEDIUM6.1DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-59548MEDIUM6.1DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-59547MEDIUM5.3DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-59546MEDIUM4.8DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-59539MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-58246MEDIUM4.3Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. Th...
CVE-2025-57639MEDIUM6.5OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the ...
CVE-2025-29084MEDIUM6.5SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu...
CVE-2025-29083MEDIUM6.5SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu...
CVE-2025-0209MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due...
CVE-2025-56304MEDIUM6.1Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.
CVE-2025-0663MEDIUM6.8A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Ada...
CVE-2025-57407MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticat...
CVE-2025-4760MEDIUM4.8An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper valida...
CVE-2025-9342MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privile...
CVE-2025-7106MEDIUM5.3danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `c...
CVE-2025-10548MEDIUM6.5The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the insta...
CVE-2025-39887MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix null-ptr-deref in bitmap_parse...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now