2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52875 | MEDIUM | 5.4 | 0.7% | Jun 23, 2025 | In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible |
| CVE-2025-48700 | MEDIUM | 6.1 | 1.8% | Jun 23, 2025 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vul... |
| CVE-2025-2172 | MEDIUM | 6.6 | 7.5% | Jun 23, 2025 | Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the inp... |
| CVE-2025-52920 | MEDIUM | 6.4 | 0.3% | Jun 23, 2025 | Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyon... |
| CVE-2025-52938 | MEDIUM | 5.1 | 0.2% | Jun 23, 2025 | Out-of-bounds Read vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with pr... |
| CVE-2025-6499 | MEDIUM | 5.5 | 0.2% | Jun 23, 2025 | A vulnerability classified as problematic was found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is th... |
| CVE-2025-6498 | MEDIUM | 5.5 | 0.2% | Jun 23, 2025 | A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAllo... |
| CVE-2025-6493 | MEDIUM | 5.5 | 0.4% | Jun 22, 2025 | A weakness has been identified in CodeMirror up to 5.65.20. Affected is an unknown function of the file mode/markdown/ma... |
| CVE-2025-6492 | MEDIUM | 5.5 | 0.4% | Jun 22, 2025 | A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is... |
| CVE-2025-6485 | MEDIUM | 6.3 | 6.0% | Jun 22, 2025 | A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the ... |
| CVE-2025-6478 | MEDIUM | 4.3 | 0.2% | Jun 22, 2025 | A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this... |
| CVE-2025-6477 | MEDIUM | 4.8 | 0.3% | Jun 22, 2025 | A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. A... |
| CVE-2025-6476 | MEDIUM | 4.3 | 0.2% | Jun 22, 2025 | A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected i... |
| CVE-2025-6475 | MEDIUM | 4.8 | 0.3% | Jun 22, 2025 | A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This iss... |
| CVE-2025-6473 | MEDIUM | 6.1 | 0.3% | Jun 22, 2025 | A vulnerability, which was classified as problematic, was found in code-projects School Fees Payment System 1.0. This af... |
| CVE-2025-6453 | MEDIUM | 4.3 | 0.4% | Jun 22, 2025 | A vulnerability classified as critical has been found in diyhi bbs 6.8. Affected is the function Add of the file /src/ma... |
| CVE-2025-6452 | MEDIUM | 4.8 | 0.3% | Jun 22, 2025 | A vulnerability was found in CodeAstro Patient Record Management System 1.0. It has been rated as problematic. This issu... |
| CVE-2025-52923 | MEDIUM | 4.3 | 0.1% | Jun 22, 2025 | Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command. |
| CVE-2025-52919 | MEDIUM | 4.3 | 0.2% | Jun 21, 2025 | In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potent... |
| CVE-2025-52918 | MEDIUM | 5 | 0.2% | Jun 21, 2025 | Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized acces... |
| CVE-2025-52917 | MEDIUM | 4.3 | 0.3% | Jun 21, 2025 | The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive req... |
| CVE-2025-1987 | MEDIUM | 6.1 | 0.5% | Jun 21, 2025 | A Cross-Site Scripting (XSS) vulnerability has been identified in Psono-Client’s handling of vault entries of type websi... |
| CVE-2025-3629 | MEDIUM | 4.3 | 0.2% | Jun 21, 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's... |
| CVE-2025-5289 | MEDIUM | 5.4 | 0.2% | Jun 21, 2025 | The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored... |
| CVE-2025-5143 | MEDIUM | 5.4 | 0.2% | Jun 21, 2025 | The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now