2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4281MEDIUM5.3A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business...
CVE-2025-45320MEDIUM5.3A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management...
CVE-2025-27921MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized...
CVE-2025-26241MEDIUM6.5A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authentica...
CVE-2025-25504MEDIUM6.5An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows ...
CVE-2025-4316MEDIUM4.3Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even i...
CVE-2025-47268MEDIUM6.5ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafte...
CVE-2025-45751MEDIUM6.1SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin...
CVE-2025-4271MEDIUM6.9A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerabi...
CVE-2025-4269MEDIUM5.3A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown proc...
CVE-2025-4268MEDIUM6.9A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unkn...
CVE-2025-3583MEDIUM4.8The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high ...
CVE-2025-39363MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlphaEfficiencyTea...
CVE-2025-4261MEDIUM5.3A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as ...
CVE-2025-20670MEDIUM5.7In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote inform...
CVE-2025-20665MEDIUM5.5In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local informa...
CVE-2025-4257MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown pro...
CVE-2025-4256MEDIUM5.4A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file ...
CVE-2025-47241MEDIUM4In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be pla...
CVE-2025-1838MEDIUM6.5IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user ...
CVE-2025-1495MEDIUM4.3IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to mis...
CVE-2025-37799MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix malformed packet sizing in vmxnet3_pro...
CVE-2025-3815MEDIUM6.4The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up...
CVE-2025-4222MEDIUM5.9The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2025-4199MEDIUM6.1The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now