2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6081MEDIUM6.8Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earli...
CVE-2025-5967MEDIUM5.3A stored cross-site scripting vulnerability in ENS HX 10.0.4 allows a malicious user to inject arbitrary HTML into the E...
CVE-2025-53096MEDIUM6.1Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks p...
CVE-2025-36056MEDIUM5.4IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 ...
CVE-2025-2141MEDIUM6.1IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 ...
CVE-2025-52996MEDIUM4.3File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52995MEDIUM6.6File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52901MEDIUM6.5File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2025-52491MEDIUM5.8Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.
CVE-2025-49493MEDIUM5.8Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
CVE-2025-52896MEDIUM5.4Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could uploa...
CVE-2025-47871MEDIUM5.4Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr...
CVE-2025-46702MEDIUM5.4Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to pr...
CVE-2025-2895MEDIUM5.4IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to...
CVE-2025-4407MEDIUM6.8Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.
CVE-2025-41439MEDIUM6.1A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Strea...
CVE-2025-40734MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker ...
CVE-2025-40733MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker ...
CVE-2025-38090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drivers/rapidio/rio_cm.c: prevent possible heap ove...
CVE-2025-38089MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processi...
CVE-2025-5730MEDIUM4.3The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could al...
CVE-2025-3745MEDIUM6.3The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links ...
CVE-2025-6883MEDIUM6.3A vulnerability classified as critical was found in code-projects Staff Audit System 1.0. This vulnerability affects unk...
CVE-2025-6870MEDIUM4.7A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this ...
CVE-2025-24292MEDIUM6.8A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VP...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now