2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-44002MEDIUM6.1Race Condition in the Directory Validation Logic in the TeamViewer Full Client and Host prior version 15.69 on Windows a...
CVE-2025-1501MEDIUM5.3An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25....
CVE-2025-48108MEDIUM6.5Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Contro...
CVE-2025-29901MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-6247MEDIUM4.7The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-57704MEDIUM5.5Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Di...
CVE-2025-9474MEDIUM4.5A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file s...
CVE-2025-9440MEDIUM6.1A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. A...
CVE-2025-9439MEDIUM6.1A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by t...
CVE-2025-9438MEDIUM6.1A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected...
CVE-2025-9434MEDIUM6.1A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects ...
CVE-2025-9433MEDIUM6.1A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/use...
CVE-2025-9432MEDIUM6.1A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admi...
CVE-2025-9431MEDIUM6.1A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation...
CVE-2025-9430MEDIUM4.8A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/o...
CVE-2025-9429MEDIUM5.4A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the fi...
CVE-2025-9422MEDIUM5.4A vulnerability was found in oitcode samarium up to 0.9.6. This impacts an unknown function of the file /dashboard/team ...
CVE-2025-57814MEDIUM5.5request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Versio...
CVE-2025-57804MEDIUM6.9h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulne...
CVE-2025-52130MEDIUM5.4File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw al...
CVE-2025-9414MEDIUM4.9A vulnerability was found in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the fi...
CVE-2025-9409MEDIUM6.5A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUplo...
CVE-2025-55574MEDIUM6.1Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code
CVE-2025-55301MEDIUM6.7The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local sto...
CVE-2025-56215MEDIUM6.5phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now