2025 CVE Vulnerabilities

45,207 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-3522MEDIUM6.3Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally....
CVE-2025-32949MEDIUM6.5This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when ex...
CVE-2025-2830MEDIUM6.3By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into inclu...
CVE-2025-28145MEDIUM6.5Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerab...
CVE-2025-28144MEDIUM6.5Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerabili...
CVE-2025-28143MEDIUM6.5Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab...
CVE-2025-28142MEDIUM6.5Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerab...
CVE-2025-27980MEDIUM6.5cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.
CVE-2025-29280MEDIUM4.8Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system ...
CVE-2025-28136MEDIUM6.5TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi.
CVE-2025-3608MEDIUM6.5A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially lea...
CVE-2025-32946MEDIUM5.3This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. Th...
CVE-2025-32945MEDIUM4.3The vulnerability allows an existing user to add playlists to a different user’s channel using the PeerTube REST API. Th...
CVE-2025-32944MEDIUM6.5The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner....
CVE-2025-32103MEDIUM5CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ ...
CVE-2025-32102MEDIUM5CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=t...
CVE-2025-30965MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue aff...
CVE-2025-30964MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forger...
CVE-2025-26990MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Server...
CVE-2025-26982MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächle...
CVE-2025-26955MEDIUM4.3Missing Authorization vulnerability in vowelweb Industrial Lite industrial-lite allows Exploiting Incorrectly Configured...
CVE-2025-26745MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSTheme RS Element...
CVE-2025-26744MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog...
CVE-2025-32943MEDIUM4.3The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server...
CVE-2025-1688MEDIUM5.5Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configurati...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now