2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6753MEDIUM6.3A vulnerability was found in huija bicycleSharingServer 1.0 and classified as critical. This issue affects the function ...
CVE-2025-6488MEDIUM6.4The isMobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ parameter in all version...
CVE-2025-45737MEDIUM6.5An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privilege...
CVE-2025-47823MEDIUM4.6Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.
CVE-2025-47822MEDIUM6.8Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper ...
CVE-2025-47821MEDIUM4.6Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.
CVE-2025-6749MEDIUM6.3A vulnerability classified as critical was found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac...
CVE-2025-47819MEDIUM6.8Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.
CVE-2025-47818MEDIUM4.6Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.
CVE-2025-6738MEDIUM6.3A vulnerability, which was classified as critical, has been found in huija bicycleSharingServer up to 7b8a3ba48ad618604a...
CVE-2025-6731MEDIUM6.3A vulnerability was found in yzcheng90 X-SpringBoot up to 5.0 and classified as critical. Affected by this issue is the ...
CVE-2025-5731MEDIUM5.5A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed ...
CVE-2025-52555MEDIUM6.5Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 th...
CVE-2025-5995MEDIUM4.6Canon EOS Webcam Utility Pro for MAC OS version 2.3d (2.3.29) and earlier contains an improper directory permissions vul...
CVE-2025-53122MEDIUM6.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon an...
CVE-2025-49592MEDIUM5.4n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. A...
CVE-2025-53121MEDIUM6.9Multiple stored XSS were found on different nodes with unsanitized parameters in OpenMNS Horizon 33.0.8 and versions ear...
CVE-2025-53013MEDIUM5.2Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9...
CVE-2025-6702MEDIUM5.3A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown fun...
CVE-2025-6701MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This issue affects some u...
CVE-2025-6700MEDIUM6.1A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of...
CVE-2025-6699MEDIUM4.1A vulnerability classified as problematic has been found in LabRedesCefetRJ WeGIA 3.4.0. This affects an unknown part of...
CVE-2025-51671MEDIUM5.4A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability ...
CVE-2025-50350MEDIUM5.4PHPGurukul Pre-School Enrollment System Project v1.0 is vulnerable to Directory Traversal in manage-classes.php.
CVE-2025-44141MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now