2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7672MEDIUM4.3The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XS...
CVE-2025-7367MEDIUM6.4The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fie...
CVE-2025-53891MEDIUM4.3The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found...
CVE-2025-53889MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to...
CVE-2025-53887MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ...
CVE-2025-53886MEDIUM4.5Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ...
CVE-2025-53885MEDIUM4.2Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ...
CVE-2025-53839MEDIUM4DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interfac...
CVE-2025-53834MEDIUM6.3Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s...
CVE-2025-53824MEDIUM5.4WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-53822MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-53821MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirec...
CVE-2025-53820MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-53640MEDIUM6.5Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Startin...
CVE-2025-52363MEDIUM6.8Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An a...
CVE-2025-7625MEDIUM4.3A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b9...
CVE-2025-51660MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.
CVE-2025-51659MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.
CVE-2025-51658MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.
CVE-2025-51657MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
CVE-2025-51656MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.
CVE-2025-51655MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
CVE-2025-51654MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.
CVE-2025-51653MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
CVE-2025-51652MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now