2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50984 | MEDIUM | 5.3 | 0.3% | Aug 27, 2025 | diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticse... |
| CVE-2025-50978 | MEDIUM | 6.1 | 0.3% | Aug 27, 2025 | In Gitblit v1.7.1, a reflected cross-site scripting (XSS) vulnerability exists in the way repository path names are hand... |
| CVE-2025-50986 | MEDIUM | 5.6 | 0.2% | Aug 27, 2025 | diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its adm... |
| CVE-2025-50985 | MEDIUM | 5.6 | 0.2% | Aug 27, 2025 | diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web in... |
| CVE-2025-56694 | MEDIUM | 5.8 | 0.4% | Aug 27, 2025 | Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to v... |
| CVE-2025-30061 | MEDIUM | 6.9 | 0.2% | Aug 27, 2025 | In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parame... |
| CVE-2025-30060 | MEDIUM | 6.9 | 0.2% | Aug 27, 2025 | In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" par... |
| CVE-2025-30059 | MEDIUM | 6.9 | 0.2% | Aug 27, 2025 | In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection. |
| CVE-2025-30058 | MEDIUM | 6.9 | 0.2% | Aug 27, 2025 | In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel"... |
| CVE-2025-30048 | MEDIUM | 5.3 | 0.2% | Aug 27, 2025 | The "serverConfig" endpoint, which returns the module configuration including credentials, is accessible without authent... |
| CVE-2025-9513 | MEDIUM | 6.3 | 0.1% | Aug 27, 2025 | A flaw has been found in editso fuso up to 1.0.4-beta.7. This affects the function PenetrateRsaAndAesHandshake of the fi... |
| CVE-2025-48081 | MEDIUM | 5.3 | 0.3% | Aug 27, 2025 | Path Traversal: '.../...//' vulnerability in Printeers Printeers Print & Ship allows Path Traversal.This issue affects P... |
| CVE-2025-49040 | MEDIUM | 4.3 | 0.1% | Aug 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery... |
| CVE-2025-49039 | MEDIUM | 5.9 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View ... |
| CVE-2025-49035 | MEDIUM | 5.9 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin... |
| CVE-2025-7732 | MEDIUM | 6.4 | 0.2% | Aug 27, 2025 | The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers... |
| CVE-2025-8490 | MEDIUM | 4.4 | 0.2% | Aug 27, 2025 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import ... |
| CVE-2025-9277 | MEDIUM | 6.4 | 0.2% | Aug 26, 2025 | The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_repla... |
| CVE-2025-35112 | MEDIUM | 4.9 | 0.3% | Aug 26, 2025 | Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an... |
| CVE-2025-26417 | MEDIUM | 4 | 0.3% | Aug 26, 2025 | In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening fil... |
| CVE-2025-22413 | MEDIUM | 4 | 0.1% | Aug 26, 2025 | In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This cou... |
| CVE-2025-22407 | MEDIUM | 5.5 | 0.1% | Aug 26, 2025 | In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. Th... |
| CVE-2025-0092 | MEDIUM | 6.5 | 0.1% | Aug 26, 2025 | In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficien... |
| CVE-2025-0086 | MEDIUM | 6.2 | 0.1% | Aug 26, 2025 | In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission c... |
| CVE-2025-0083 | MEDIUM | 4 | 0.1% | Aug 26, 2025 | In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now