2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-0082MEDIUM5.5In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across us...
CVE-2025-50975MEDIUM5.4IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT...
CVE-2025-57818MEDIUM6.3Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to version 2.0.1, a server-side reques...
CVE-2025-50976MEDIUM6.1IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK,...
CVE-2025-57425MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability in SourceCodester FAQ Management System 1.0 allows an authenticated at...
CVE-2025-52184MEDIUM6.1Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic...
CVE-2025-50974MEDIUM6.5The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied...
CVE-2025-1494MEDIUM6.1IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim....
CVE-2025-57813MEDIUM5.9traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists wh...
CVE-2025-56432MEDIUM6.1A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to exec...
CVE-2025-52219MEDIUM6.5SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fie...
CVE-2025-52217MEDIUM5.4SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly hand...
CVE-2025-52037MEDIUM6.1A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.p...
CVE-2025-52036MEDIUM6.1A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.p...
CVE-2025-52035MEDIUM6.1A vulnerability in NotesCMS and specifically in the page /index.php?route=notes. The manipulation of the title of the se...
CVE-2025-25737MEDIUM6.8Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were disco...
CVE-2025-25736MEDIUM6.8Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android ...
CVE-2025-25735MEDIUM4.6Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were disco...
CVE-2025-25734MEDIUM6.8Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discov...
CVE-2025-25732MEDIUM6.8Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.8...
CVE-2025-9190MEDIUM4.8The configuration of Cursor on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileg...
CVE-2025-8700MEDIUM4.8Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", al...
CVE-2025-8597MEDIUM4.8MacVim's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows lo...
CVE-2025-53813MEDIUM4.8The configuration of Nozbe on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivilege...
CVE-2025-53811MEDIUM4.8The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivil...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now