2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-52883MEDIUM5.3Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacke...
CVE-2025-6557MEDIUM5.4Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker wh...
CVE-2025-6556MEDIUM5.4Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass co...
CVE-2025-6555MEDIUM5.4Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit hea...
CVE-2025-53021MEDIUM4.2A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions ...
CVE-2025-52880MEDIUM4.2Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has be...
CVE-2025-5087MEDIUM6Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insecurely using zlib-compressed data over HTTP. An attacker capa...
CVE-2025-53073MEDIUM4.2In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorize...
CVE-2025-49147MEDIUM5.3Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 a...
CVE-2025-23260MEDIUM4.3NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using t...
CVE-2025-50699MEDIUM6.1PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in odms/admin/view-user-q...
CVE-2025-50695MEDIUM6.1PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in /admin/view-booking-de...
CVE-2025-50693MEDIUM6.5PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/requ...
CVE-2025-6569MEDIUM6.1A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vu...
CVE-2025-5318MEDIUM5.4A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_...
CVE-2025-6434MEDIUM4.3The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking ...
CVE-2025-6431MEDIUM6.5When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing...
CVE-2025-6430MEDIUM6.1When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was ...
CVE-2025-6429MEDIUM6.5Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in...
CVE-2025-6428MEDIUM4.3When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correc...
CVE-2025-6425MEDIUM4.3An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified ...
CVE-2025-39201MEDIUM6.1A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to...
CVE-2025-5258MEDIUM6.4The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter...
CVE-2025-43877MEDIUM5.4WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be...
CVE-2025-36519MEDIUM5.3Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now