2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10674MEDIUM4.3A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController o...
CVE-2025-59417MEDIUM6.1Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site sc...
CVE-2025-59040MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representa...
CVE-2025-57452MEDIUM6.1In realme BackupRestore app v15.1.12_2810c08_250314, improper URI scheme handling in com.coloros.pc.PcToolMainActivity a...
CVE-2025-55911MEDIUM6.5An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an...
CVE-2025-4444MEDIUM6.3A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Oni...
CVE-2025-10669MEDIUM6.3A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component...
CVE-2025-40678MEDIUM5.3Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability ...
CVE-2025-9992MEDIUM6.4The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-0547MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof...
CVE-2025-10493MEDIUM5.3The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via t...
CVE-2025-10642MEDIUM5.1A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts...
CVE-2025-10632MEDIUM5.4A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unk...
CVE-2025-10631MEDIUM5.4A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of ...
CVE-2025-23337MEDIUM6.7NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a mal...
CVE-2025-59415MEDIUM5.4Frappe Learning is a learning system that helps users structure their content. In versions 2.34.1 and below, there is a ...
CVE-2025-10619MEDIUM6.3A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of th...
CVE-2025-59354MEDIUM5.3Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 us...
CVE-2025-59351MEDIUM5.3Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return ...
CVE-2025-59350MEDIUM5.3Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access contro...
CVE-2025-59347MEDIUM6.5Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disab...
CVE-2025-59346MEDIUM5.3Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a...
CVE-2025-37122MEDIUM6.1A vulnerability in the web-based management interface of network access control services could allow an unauthenticated ...
CVE-2025-10614MEDIUM6.1A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This a...
CVE-2025-56648MEDIUM6.5npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPReque...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now