2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-50984MEDIUM5.3diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticse...
CVE-2025-50978MEDIUM6.1In Gitblit v1.7.1, a reflected cross-site scripting (XSS) vulnerability exists in the way repository path names are hand...
CVE-2025-50986MEDIUM5.6diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its adm...
CVE-2025-50985MEDIUM5.6diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web in...
CVE-2025-56694MEDIUM5.8Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to v...
CVE-2025-30061MEDIUM6.9In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parame...
CVE-2025-30060MEDIUM6.9In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" par...
CVE-2025-30059MEDIUM6.9In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection.
CVE-2025-30058MEDIUM6.9In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel"...
CVE-2025-30048MEDIUM5.3The "serverConfig" endpoint, which returns the module configuration including credentials, is accessible without authent...
CVE-2025-9513MEDIUM6.3A flaw has been found in editso fuso up to 1.0.4-beta.7. This affects the function PenetrateRsaAndAesHandshake of the fi...
CVE-2025-48081MEDIUM5.3Path Traversal: '.../...//' vulnerability in Printeers Printeers Print & Ship allows Path Traversal.This issue affects P...
CVE-2025-49040MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery...
CVE-2025-49039MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View ...
CVE-2025-49035MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin...
CVE-2025-7732MEDIUM6.4The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers...
CVE-2025-8490MEDIUM4.4The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import ...
CVE-2025-9277MEDIUM6.4The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_repla...
CVE-2025-35112MEDIUM4.9Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an...
CVE-2025-26417MEDIUM4In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening fil...
CVE-2025-22413MEDIUM4In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This cou...
CVE-2025-22407MEDIUM5.5In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. Th...
CVE-2025-0092MEDIUM6.5In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficien...
CVE-2025-0086MEDIUM6.2In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission c...
CVE-2025-0083MEDIUM4In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now