2025 CVE Vulnerabilities

45,343 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9806MEDIUM6.4A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /et...
CVE-2025-58162MEDIUM6.5MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a special...
CVE-2025-58161MEDIUM4.3MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path ve...
CVE-2025-9802MEDIUM5.1A vulnerability was detected in RemoteClinic 2.0. This vulnerability affects unknown code of the file /staff/profile.php...
CVE-2025-9800MEDIUM6.1A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue...
CVE-2025-9799MEDIUM5A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChang...
CVE-2025-9796MEDIUM4.1A vulnerability was found in thinkgem JeeSite up to 5.12.1. This affects the function decodeUrl2 of the file common/src/...
CVE-2025-9795MEDIUM5.4A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the...
CVE-2025-9810MEDIUM5.8TOCTOU  in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions ...
CVE-2025-9375MEDIUM6.9XML Injection vulnerability in xmltodict allows Input Data Manipulation. This issue affects xmltodict: from 0.14.2 befor...
CVE-2025-55007MEDIUM5.3Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to s...
CVE-2025-33099MEDIUM5.9IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the ...
CVE-2025-33084MEDIUM5.9IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the fa...
CVE-2025-33083MEDIUM5.4IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticat...
CVE-2025-33082MEDIUM5.4IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticat...
CVE-2025-0656MEDIUM6.1IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthentic...
CVE-2025-36133MEDIUM5.5IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 th...
CVE-2025-9774MEDIUM4.3A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patien...
CVE-2025-9773MEDIUM6.1A flaw has been found in RemoteClinic up to 2.0. This vulnerability affects unknown code of the file /staff/edit.php. Ex...
CVE-2025-9769MEDIUM6.2A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng...
CVE-2025-58318MEDIUM5.9Delta Electronics DIAView has an authentication bypass vulnerability.
CVE-2025-20707MEDIUM6.7In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil...
CVE-2025-20703MEDIUM6.5In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of s...
CVE-2025-9570MEDIUM6.9The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administra...
CVE-2025-9569MEDIUM6.1The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attacke...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now