2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-55589MEDIUM6.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the ma...
CVE-2025-55585MEDIUM6.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.
CVE-2025-55584MEDIUM5.3TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root acc...
CVE-2025-43731MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025...
CVE-2025-55296MEDIUM5.4librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability ...
CVE-2025-55288MEDIUM5.4Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Reflected Cross-Site Scripting (XSS) vulnerabi...
CVE-2025-55287MEDIUM5.4Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Stored Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-55214MEDIUM6.9Copier library and CLI app for rendering project templates. From 7.1.0 to before 9.9.1, Copier suggests that it's safe t...
CVE-2025-54421MEDIUM5.4NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab...
CVE-2025-54118MEDIUM5.3NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in...
CVE-2025-54117MEDIUM5.4NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab...
CVE-2025-43733MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through ...
CVE-2025-41242MEDIUM5.9Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant...
CVE-2025-57703MEDIUM6.1DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57702MEDIUM6.1DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57701MEDIUM6.1DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57700MEDIUM6.1DIAEnergie - Stored Cross-site Scripting
CVE-2025-9108MEDIUM4.3Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ...
CVE-2025-9107MEDIUM6.1A vulnerability was determined in Portabilis i-Diario up to 1.5.0. This impacts an unknown function of the file /alunos/...
CVE-2025-9106MEDIUM5.4A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-en...
CVE-2025-9105MEDIUM5.4A vulnerability has been found in Portabilis i-Diario up to 1.5.0. The impacted element is an unknown function of the fi...
CVE-2025-9104MEDIUM5.4A flaw has been found in Portabilis i-Diario up to 1.5.0. The affected element is an unknown function of the file /plano...
CVE-2025-9102MEDIUM5.5A security vulnerability has been detected in 1&1 Mail & Media mail.com App 8.8.0 on Android. Affected is an unknown fun...
CVE-2025-9101MEDIUM5.4A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file...
CVE-2025-9099MEDIUM6.3A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now