2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-57104MEDIUM5.4Teampel 5.1.6 is vulnerable to SQL Injection in /Common/login.aspx.
CVE-2025-49089MEDIUM6.3wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd...
CVE-2025-43792MEDIUM5.3Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 202...
CVE-2025-59397MEDIUM5Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.
CVE-2025-56252MEDIUM6.1Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute arbitrary code via a crafted...
CVE-2025-52048MEDIUM6.5In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py...
CVE-2025-8396MEDIUM6.9Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server o...
CVE-2025-59376MEDIUM5.3feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-writ...
CVE-2025-39801MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Remove WARN_ON for device endpoint comma...
CVE-2025-39800MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on unexpected eb generatio...
CVE-2025-43794MEDIUM4.8Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported version...
CVE-2025-9826MEDIUM5.4Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to caus...
CVE-2025-9084MEDIUM6.1Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to...
CVE-2025-9072MEDIUM5.4Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, a...
CVE-2025-10441MEDIUM6.3A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the...
CVE-2025-9078MEDIUM4.3Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to ...
CVE-2025-9076MEDIUM6.5Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronizat...
CVE-2025-10440MEDIUM6.3A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A...
CVE-2025-41713MEDIUM6.5During a short time frame while the device is booting an unauthenticated remote attacker can send traffic to unauthorize...
CVE-2025-10433MEDIUM6.3A vulnerability was determined in 1Panel-dev MaxKB up to 2.0.2/2.1.0. This issue affects some unknown processing of the ...
CVE-2025-59378MEDIUM5.7In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program th...
CVE-2025-10453MEDIUM6.9O'View MapServer developed by PilotGaea Technologies has a Server-Side Request Forgery vulnerability, allowing unauthent...
CVE-2025-10422MEDIUM4.3A vulnerability has been found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. This issue affects the fun...
CVE-2025-59364MEDIUM5.3The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth...
CVE-2025-10411MEDIUM6.1A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affect...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now