2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-47943MEDIUM6.3Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-sit...
CVE-2025-6552MEDIUM4.3A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the functio...
CVE-2025-48470MEDIUM4.1Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scr...
CVE-2025-48468MEDIUM6.4Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to ...
CVE-2025-48467MEDIUM6.5Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to r...
CVE-2025-48462MEDIUM4.2Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block ot...
CVE-2025-48461MEDIUM5Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and...
CVE-2025-6551MEDIUM5.4A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function ...
CVE-2025-6534MEDIUM6.8A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affect...
CVE-2025-34032MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the ...
CVE-2025-6533MEDIUM5.9A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected ...
CVE-2025-6532MEDIUM4.3A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerabili...
CVE-2025-6531MEDIUM4.3A vulnerability was found in SIFUSM/MZZYG BD S1 up to 20250611. It has been declared as problematic. This vulnerability ...
CVE-2025-6530MEDIUM4.8A vulnerability was found in 70mai M300 up to 20250611. It has been classified as problematic. This affects an unknown p...
CVE-2025-6528MEDIUM4.3A vulnerability has been found in 70mai M300 up to 20250611 and classified as problematic. Affected by this vulnerabilit...
CVE-2025-6526MEDIUM5.3A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects so...
CVE-2025-6525MEDIUM4.3A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code ...
CVE-2025-52561MEDIUM6.9HTMLSanitizer.jl is a Whitelist-based HTML sanitizer. Prior to version 0.2.1, when adding the style tag to the whitelist...
CVE-2025-49574MEDIUM6.4Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1,...
CVE-2025-6518MEDIUM6.3A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the functio...
CVE-2025-52967MEDIUM5.8gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.
CVE-2025-52879MEDIUM4.8In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
CVE-2025-52878MEDIUM4.3In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
CVE-2025-52877MEDIUM4.8In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
CVE-2025-52876MEDIUM5.4In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now