2025 CVE Vulnerabilities

45,343 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-55824MEDIUM6.5ModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execut...
CVE-2025-55476MEDIUM6.5FireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint...
CVE-2025-51966MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in the PDF preview functionality of uTools thru 7.1.1. When a user pre...
CVE-2025-50565MEDIUM6.5Doubo ERP 1.0 has an SQL injection vulnerability due to a lack of filtering of user input, which can be remotely initiat...
CVE-2025-32100MEDIUM6.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-32098MEDIUM5.3An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges ...
CVE-2025-9828MEDIUM5.9A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the compone...
CVE-2025-55474MEDIUM6.1Many Notes 0.10.1 is vulnerable to Cross Site Scripting (XSS), which allows malicious Markdown files to execute JavaScri...
CVE-2025-55473MEDIUM6.1Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scriptin...
CVE-2025-55472MEDIUM6.5SQL Injection vulnerability exists in Tirreno v0.9.5, specifically in the /admin/loadUsers API endpoint. The vulnerabili...
CVE-2025-55373MEDIUM5.3Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to...
CVE-2025-57611MEDIUM5.3An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the dump() ...
CVE-2025-55372MEDIUM5.3An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code vi...
CVE-2025-50757MEDIUM6.5Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the user...
CVE-2025-50755MEDIUM6.5Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the comm...
CVE-2025-46047MEDIUM6.5A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows...
CVE-2025-0670MEDIUM4.7Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft ProKuafor allows Resource Leak Exposure. Thi...
CVE-2025-56254MEDIUM4.3PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in lea...
CVE-2025-52548MEDIUM4.9E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enab...
CVE-2025-52546MEDIUM6.1E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta...
CVE-2025-0640MEDIUM4.7Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft OctoCloud allows Resource Leak Exposure. Thi...
CVE-2025-41031MEDIUM6.9Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other us...
CVE-2025-41030MEDIUM6.9Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain informat...
CVE-2025-44017MEDIUM5.1"Gunosy" App contains a vulnerability where sensitive information may be included in the application's outbound communic...
CVE-2025-8662MEDIUM4.3OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tamp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now