2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-52875MEDIUM5.4In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible
CVE-2025-48700MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vul...
CVE-2025-2172MEDIUM6.6Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the inp...
CVE-2025-52920MEDIUM6.4Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyon...
CVE-2025-52938MEDIUM5.1Out-of-bounds Read vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with pr...
CVE-2025-6499MEDIUM5.5A vulnerability classified as problematic was found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is th...
CVE-2025-6498MEDIUM5.5A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAllo...
CVE-2025-6493MEDIUM5.5A weakness has been identified in CodeMirror up to 5.65.20. Affected is an unknown function of the file mode/markdown/ma...
CVE-2025-6492MEDIUM5.5A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is...
CVE-2025-6485MEDIUM6.3A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the ...
CVE-2025-6478MEDIUM4.3A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this...
CVE-2025-6477MEDIUM4.8A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. A...
CVE-2025-6476MEDIUM4.3A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected i...
CVE-2025-6475MEDIUM4.8A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This iss...
CVE-2025-6473MEDIUM6.1A vulnerability, which was classified as problematic, was found in code-projects School Fees Payment System 1.0. This af...
CVE-2025-6453MEDIUM4.3A vulnerability classified as critical has been found in diyhi bbs 6.8. Affected is the function Add of the file /src/ma...
CVE-2025-6452MEDIUM4.8A vulnerability was found in CodeAstro Patient Record Management System 1.0. It has been rated as problematic. This issu...
CVE-2025-52923MEDIUM4.3Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.
CVE-2025-52919MEDIUM4.3In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potent...
CVE-2025-52918MEDIUM5Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized acces...
CVE-2025-52917MEDIUM4.3The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive req...
CVE-2025-1987MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability has been identified in Psono-Client’s handling of vault entries of type websi...
CVE-2025-3629MEDIUM4.3IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's...
CVE-2025-5289MEDIUM5.4The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored...
CVE-2025-5143MEDIUM5.4The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now