2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53889MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to...
CVE-2025-53887MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ...
CVE-2025-53886MEDIUM4.5Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ...
CVE-2025-53885MEDIUM4.2Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ...
CVE-2025-53839MEDIUM4DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interfac...
CVE-2025-53834MEDIUM6.3Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s...
CVE-2025-53824MEDIUM5.4WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-53822MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-53821MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirec...
CVE-2025-53820MEDIUM6.1WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro...
CVE-2025-53640MEDIUM6.5Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Startin...
CVE-2025-52363MEDIUM6.8Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An a...
CVE-2025-7625MEDIUM4.3A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b9...
CVE-2025-51660MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.
CVE-2025-51659MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.
CVE-2025-51658MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.
CVE-2025-51657MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
CVE-2025-51656MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.
CVE-2025-51655MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
CVE-2025-51654MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.
CVE-2025-51653MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
CVE-2025-51652MEDIUM5.4SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.
CVE-2025-51651MEDIUM5.5An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attack...
CVE-2025-51650MEDIUM5.6An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to ...
CVE-2025-7519MEDIUM6.7A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds wri...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now