2025 CVE Vulnerabilities

45,345 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9308MEDIUM5.5A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/...
CVE-2025-9306MEDIUM5.4A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown...
CVE-2025-9162MEDIUM4.9A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes pla...
CVE-2025-57753MEDIUM6vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible...
CVE-2025-55744MEDIUM4.3UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some ...
CVE-2025-55742MEDIUM4.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPi...
CVE-2025-55371MEDIUM5.3Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers...
CVE-2025-50860MEDIUM5.4SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers ...
CVE-2025-55367MEDIUM5.3Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attacke...
CVE-2025-55366MEDIUM5.3Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily...
CVE-2025-51818MEDIUM5.4MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute ar...
CVE-2025-47184MEDIUM5.3An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 ...
CVE-2025-8064MEDIUM6.4The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘selector_height’ parame...
CVE-2025-8023MEDIUM4.9Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path trave...
CVE-2025-49810MEDIUM4.3Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thre...
CVE-2025-49222MEDIUM6.8Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to ...
CVE-2025-47870MEDIUM4.3Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team in...
CVE-2025-36530MEDIUM4.9Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate fi...
CVE-2025-8607MEDIUM6.4The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross...
CVE-2025-7221MEDIUM4.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2025-53505MEDIUM5.3Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerabil...
CVE-2025-53504MEDIUM5.4Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vuln...
CVE-2025-48355MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ProveSource LTD ProveSource ...
CVE-2025-27213MEDIUM4.9An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to en...
CVE-2025-9264MEDIUM5.4A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now