2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9273MEDIUM4.3CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers...
CVE-2025-36162MEDIUM4.3IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive ...
CVE-2025-55824MEDIUM6.5ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execut...
CVE-2025-55476MEDIUM6.5FireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint...
CVE-2025-51966MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in the PDF preview functionality of uTools thru 7.1.1. When a user pre...
CVE-2025-50565MEDIUM6.5Doubo ERP 1.0 has an SQL injection vulnerability due to a lack of filtering of user input, which can be remotely initiat...
CVE-2025-32100MEDIUM6.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-32098MEDIUM5.3An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges ...
CVE-2025-9828MEDIUM5.9A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the compone...
CVE-2025-55474MEDIUM6.1Many Notes 0.10.1 is vulnerable to Cross Site Scripting (XSS), which allows malicious Markdown files to execute JavaScri...
CVE-2025-55473MEDIUM6.1Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scriptin...
CVE-2025-55472MEDIUM6.5SQL Injection vulnerability exists in Tirreno v0.9.5, specifically in the /admin/loadUsers API endpoint. The vulnerabili...
CVE-2025-55373MEDIUM5.3Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to...
CVE-2025-57611MEDIUM5.3An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the dump() ...
CVE-2025-55372MEDIUM5.3An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code vi...
CVE-2025-50757MEDIUM6.5Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the user...
CVE-2025-50755MEDIUM6.5Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the comm...
CVE-2025-46047MEDIUM6.5A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows...
CVE-2025-0670MEDIUM4.7Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft ProKuafor allows Resource Leak Exposure. Thi...
CVE-2025-56254MEDIUM4.3PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in lea...
CVE-2025-52548MEDIUM4.9E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enab...
CVE-2025-52546MEDIUM6.1E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta...
CVE-2025-0640MEDIUM4.7Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft OctoCloud allows Resource Leak Exposure. Thi...
CVE-2025-41031MEDIUM6.9Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other us...
CVE-2025-41030MEDIUM6.9Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain informat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now