2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-50592MEDIUM5.4Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
CVE-2025-45512MEDIUM6.5A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attack...
CVE-2025-51857MEDIUM6.1The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS a...
CVE-2025-51627MEDIUM6.5Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-le...
CVE-2025-51060MEDIUM6.5An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0...
CVE-2025-50688MEDIUM6.5A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file u...
CVE-2025-50454MEDIUM6.5An Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an unauthorized attacker to log ...
CVE-2025-8585MEDIUM5.3A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the fun...
CVE-2025-43980MEDIUM6.5An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN. They enable the SSH service by default with the ...
CVE-2025-47152MEDIUM6.5An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396...
CVE-2025-46958MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-27931MEDIUM6.5An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using ...
CVE-2025-8555MEDIUM5.4A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown funct...
CVE-2025-8554MEDIUM5.4A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some...
CVE-2025-8553MEDIUM5.4A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code ...
CVE-2025-8552MEDIUM5.4A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the...
CVE-2025-8551MEDIUM5.4A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some u...
CVE-2025-8295MEDIUM6.4The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ paramete...
CVE-2025-8294MEDIUM6.4The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all v...
CVE-2025-2810MEDIUM5.5A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.
CVE-2025-8550MEDIUM5.4A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerabilit...
CVE-2025-8315MEDIUM6.4The WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter i...
CVE-2025-8313MEDIUM6.4The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter ...
CVE-2025-8547MEDIUM5.5A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown...
CVE-2025-8546MEDIUM5.5A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function ad...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now