2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-51651MEDIUM5.5An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attack...
CVE-2025-51650MEDIUM5.6An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to ...
CVE-2025-7519MEDIUM6.7A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds wri...
CVE-2025-7601MEDIUM5.4A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vu...
CVE-2025-7618MEDIUM4.8A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. A...
CVE-2025-24391MEDIUM5.3A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts th...
CVE-2025-7579MEDIUM4.3A vulnerability was found in chinese-poetry 0.1. It has been rated as problematic. This issue affects some unknown proce...
CVE-2025-7578MEDIUM5A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been declared as critical....
CVE-2025-7575MEDIUM5.1A vulnerability has been found in Zavy86 WikiDocs up to 1.0.77 and classified as critical. Affected by this vulnerabilit...
CVE-2025-7380MEDIUM4.8A stored Cross-Site Scripting (XSS) vulnerability exists in the Access Control of ADM, the issue allows an attacker to i...
CVE-2025-7573MEDIUM5.5A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1...
CVE-2025-7572MEDIUM5.5A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P a...
CVE-2025-29606MEDIUM4.3py-libp2p before 0.2.3 allows a peer to cause a denial of service (resource consumption) via a large RSA key.
CVE-2025-7567MEDIUM4.3A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processin...
CVE-2025-7552MEDIUM6.3A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the...
CVE-2025-1220MEDIUM5.3In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like f...
CVE-2025-6491MEDIUM5.9In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data...
CVE-2025-53865MEDIUM6.4In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).
CVE-2025-7511MEDIUM6.5A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown p...
CVE-2025-7488MEDIUM4.3A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and cl...
CVE-2025-7487MEDIUM6.3A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f71...
CVE-2025-7485MEDIUM4.8A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the functi...
CVE-2025-36104MEDIUM6.5IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due t...
CVE-2025-7518MEDIUM4.9The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via th...
CVE-2025-7464MEDIUM6.3A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now