2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-49162MEDIUM6.4Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a ...
CVE-2025-3919MEDIUM6.4The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2025-48996MEDIUM5.3HAX open-apis provides microservice apis for HAX webcomponents repo that are shared infrastructure calls. An unauthentic...
CVE-2025-47585MEDIUM6.5Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme...
CVE-2025-49069MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in cimatti Contact Forms by Cimatti contact-forms allows Cross Site Requ...
CVE-2025-45387MEDIUM5.4osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.
CVE-2025-27955MEDIUM6.5Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and...
CVE-2025-27954MEDIUM6.5An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execut...
CVE-2025-27953MEDIUM6.5An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execut...
CVE-2025-23104MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privi...
CVE-2025-20297MEDIUM5.4In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2...
CVE-2025-48995MEDIUM6.9SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificat...
CVE-2025-48994MEDIUM6.9SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificat...
CVE-2025-48941MEDIUM5.3MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions...
CVE-2025-44115MEDIUM5.4A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&...
CVE-2025-44172MEDIUM6.5Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement ...
CVE-2025-20001MEDIUM6.5An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trig...
CVE-2025-46806MEDIUM6.9A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue a...
CVE-2025-48958MEDIUM5.4Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the cu...
CVE-2025-48955MEDIUM6.2Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers...
CVE-2025-48495MEDIUM5.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. By renaming the friendly n...
CVE-2025-48494MEDIUM5.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. When using end-to-end encr...
CVE-2025-47272MEDIUM5.5The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to ...
CVE-2025-3454MEDIUM5This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash...
CVE-2025-5437MEDIUM6.9A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now