2025 CVE Vulnerabilities

45,345 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-50986MEDIUM5.6diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its adm...
CVE-2025-50985MEDIUM5.6diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web in...
CVE-2025-56694MEDIUM5.8Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to v...
CVE-2025-30061MEDIUM6.9In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parame...
CVE-2025-30060MEDIUM6.9In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" par...
CVE-2025-30059MEDIUM6.9In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection.
CVE-2025-30058MEDIUM6.9In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel"...
CVE-2025-30048MEDIUM5.3The "serverConfig" endpoint, which returns the module configuration including credentials, is accessible without authent...
CVE-2025-9513MEDIUM6.3A flaw has been found in editso fuso up to 1.0.4-beta.7. This affects the function PenetrateRsaAndAesHandshake of the fi...
CVE-2025-48081MEDIUM5.3Path Traversal: '.../...//' vulnerability in Printeers Printeers Print & Ship allows Path Traversal.This issue affects P...
CVE-2025-49040MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery...
CVE-2025-49039MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View ...
CVE-2025-49035MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin...
CVE-2025-7732MEDIUM6.4The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers...
CVE-2025-8490MEDIUM4.4The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import ...
CVE-2025-9277MEDIUM6.4The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_repla...
CVE-2025-35112MEDIUM4.9Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an...
CVE-2025-26417MEDIUM4In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening fil...
CVE-2025-22413MEDIUM4In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This cou...
CVE-2025-22407MEDIUM5.5In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. Th...
CVE-2025-0092MEDIUM6.5In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficien...
CVE-2025-0086MEDIUM6.2In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission c...
CVE-2025-0083MEDIUM4In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This c...
CVE-2025-0082MEDIUM5.5In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across us...
CVE-2025-50975MEDIUM5.4IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now