2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-63783HIGH7.6A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delet...
CVE-2025-63691CRITICAL9.6In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the...
CVE-2025-63690CRITICAL9.1In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the sy...
CVE-2025-63689CRITICAL10Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e...
CVE-2025-63687MEDIUM6.5An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/...
CVE-2025-63686MEDIUM6.5There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c938116...
CVE-2025-58469HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can the...
CVE-2025-58465MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a us...
CVE-2025-58464HIGH7.5A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit...
CVE-2025-58463MEDIUM4.9A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an admi...
CVE-2025-57712MEDIUM6.5A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...
CVE-2025-57706MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user...
CVE-2025-54168MEDIUM4.8A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an admin...
CVE-2025-54167HIGH7.2A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains a...
CVE-2025-53413MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53412MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-53411MEDIUM4.9An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53410MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53409MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-53408MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-52865MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a...
CVE-2025-52425CRITICAL9.8An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to e...
CVE-2025-47207MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gain...
CVE-2025-12861HIGH7.2A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the...
CVE-2025-12860HIGH7.2A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now