2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30084MEDIUM6.1A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the...
CVE-2025-27754MEDIUM6.5A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows auth...
CVE-2025-27753MEDIUM6.5A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to th...
CVE-2025-27445MEDIUM5.4A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allow...
CVE-2025-0691MEDIUM5Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated u...
CVE-2025-5341MEDIUM6.4The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2025-5651MEDIUM5.4A vulnerability, which was classified as problematic, has been found in code-projects Traffic Offense Reporting System 1...
CVE-2025-5649MEDIUM6.5A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affec...
CVE-2025-5683MEDIUM5.5When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects ...
CVE-2025-5640MEDIUM4.8A vulnerability was found in PX4-Autopilot 1.12.3. It has been classified as problematic. This affects the function Mavl...
CVE-2025-49466MEDIUM5.8aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the n...
CVE-2025-48432MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response log...
CVE-2025-5628MEDIUM5.4A vulnerability, which was classified as problematic, has been found in SourceCodester Food Menu Manager 1.0. Affected b...
CVE-2025-49007MEDIUM5.3Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of...
CVE-2025-5690MEDIUM6.5PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass the masking rules define...
CVE-2025-48934MEDIUM5.3Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the `Deno.env.toObject` ...
CVE-2025-48888MEDIUM5.3Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2....
CVE-2025-46339MEDIUM4.3FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding ...
CVE-2025-46204MEDIUM6.5An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
CVE-2025-46203MEDIUM6.5An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
CVE-2025-46011MEDIUM6.5Listmonk v4.1.0 (fixed in v5.0.0) is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers...
CVE-2025-32015MEDIUM6.7FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, HTML is sanitized improperly inside the `<iframe...
CVE-2025-31482MEDIUM4.3FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedl...
CVE-2025-31136MEDIUM5.4FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to run arbitrary JavaScript on the...
CVE-2025-22245MEDIUM5.9VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validatio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now