2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48738MEDIUM6.9An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, an...
CVE-2025-48735MEDIUM4.3A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230...
CVE-2025-46176MEDIUM6.5Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotel...
CVE-2025-44998MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows...
CVE-2025-48378MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-48377MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-48375MEDIUM5.3Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equiva...
CVE-2025-32967MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. A logging overs...
CVE-2025-3580MEDIUM5.5An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently dele...
CVE-2025-48275MEDIUM6.5Missing Authorization vulnerability in dastan800 Visual Header visual-header allows Exploiting Incorrectly Configured Ac...
CVE-2025-48271MEDIUM6.5Missing Authorization vulnerability in Leadinfo Leadinfo leadinfo allows Exploiting Incorrectly Configured Access Contro...
CVE-2025-47619MEDIUM6.5Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affec...
CVE-2025-47529MEDIUM6.5Missing Authorization vulnerability in UX Design Experts Experto CTA Widget – Call To Action, Sticky CTA, Floating Butto...
CVE-2025-47513MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CR...
CVE-2025-46527MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press likec...
CVE-2025-46518MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT R...
CVE-2025-46493MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Cr...
CVE-2025-46486MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay ...
CVE-2025-41380MEDIUM6.1Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a loca...
CVE-2025-41379MEDIUM6.3The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an associated ID, but there is a ...
CVE-2025-41378MEDIUM6.9The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf file. This can be exploi...
CVE-2025-3894MEDIUM4.8Text editor embedded into MegaBIP software does not neutralize user input allowing Stored XSS attacks on other users. In...
CVE-2025-4379MEDIUM5.1DobryCMS in versions 2.* and lower is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in s...
CVE-2025-5096MEDIUM5.4The TablePress plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the 'data-caption', 'data...
CVE-2025-47149MEDIUM6.9The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If expl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now