2025 CVE Vulnerabilities

45,343 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-41044MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...
CVE-2025-41043MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...
CVE-2025-41042MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...
CVE-2025-41041MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...
CVE-2025-41040MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...
CVE-2025-41039MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...
CVE-2025-41038MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...
CVE-2025-41037MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...
CVE-2025-41036MEDIUM5.4A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack...
CVE-2025-41035MEDIUM6.5A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/dow...
CVE-2025-9940MEDIUM5.4A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the fil...
CVE-2025-9939MEDIUM5.4A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an un...
CVE-2025-9937MEDIUM5.4A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalSto...
CVE-2025-9936MEDIUM4.3A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the f...
CVE-2025-9931MEDIUM6.1A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!chang...
CVE-2025-9929MEDIUM4.8A weakness has been identified in code-projects Responsive Blog Site 1.0. This affects an unknown function of the file b...
CVE-2025-9616MEDIUM5.3The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. ...
CVE-2025-9516MEDIUM4.9The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 vi...
CVE-2025-9467MEDIUM5.3When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass ...
CVE-2025-36909MEDIUM5.3Information disclosure
CVE-2025-36908MEDIUM6.7In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. ...
CVE-2025-36902MEDIUM6.7In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overfl...
CVE-2025-36900MEDIUM6.7In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lea...
CVE-2025-36893MEDIUM5.5In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could ...
CVE-2025-8268MEDIUM6.5The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability che...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now