2025 CVE Vulnerabilities

45,170 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-44017MEDIUM5.1"Gunosy" App contains a vulnerability where sensitive information may be included in the application's outbound communic...
CVE-2025-8662MEDIUM4.3OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tamp...
CVE-2025-9806MEDIUM6.4A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /et...
CVE-2025-58162MEDIUM6.5MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a special...
CVE-2025-58161MEDIUM4.3MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path ve...
CVE-2025-9802MEDIUM5.1A vulnerability was detected in RemoteClinic 2.0. This vulnerability affects unknown code of the file /staff/profile.php...
CVE-2025-9800MEDIUM6.1A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue...
CVE-2025-9799MEDIUM5A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChang...
CVE-2025-9796MEDIUM4.1A vulnerability was found in thinkgem JeeSite up to 5.12.1. This affects the function decodeUrl2 of the file common/src/...
CVE-2025-9795MEDIUM5.4A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the...
CVE-2025-9810MEDIUM5.8TOCTOU  in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions ...
CVE-2025-9375MEDIUM6.9XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 befor...
CVE-2025-55007MEDIUM5.3Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to s...
CVE-2025-33099MEDIUM5.9IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the ...
CVE-2025-33084MEDIUM5.9IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the fa...
CVE-2025-33083MEDIUM5.4IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticat...
CVE-2025-33082MEDIUM5.4IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticat...
CVE-2025-0656MEDIUM6.1IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthentic...
CVE-2025-36133MEDIUM5.5IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 th...
CVE-2025-9774MEDIUM4.3A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patien...
CVE-2025-9773MEDIUM6.1A flaw has been found in RemoteClinic up to 2.0. This vulnerability affects unknown code of the file /staff/edit.php. Ex...
CVE-2025-9769MEDIUM6.2A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng...
CVE-2025-58318MEDIUM5.9Delta Electronics DIAView has an authentication bypass vulnerability.
CVE-2025-20707MEDIUM6.7In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil...
CVE-2025-20703MEDIUM6.5In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of s...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now