2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30138MEDIUM4.6An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging ...
CVE-2025-29930MEDIUM6.9imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] param...
CVE-2025-29790MEDIUM5.4Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and...
CVE-2025-27080MEDIUM6Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive...
CVE-2025-25042MEDIUM4.3A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view se...
CVE-2025-2487MEDIUM4.9A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the l...
CVE-2025-26138MEDIUM6.5Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.asp...
CVE-2025-25586MEDIUM4.2yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources...
CVE-2025-25582MEDIUM6.1yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /...
CVE-2025-30110MEDIUM6.5On IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism reli...
CVE-2025-30109MEDIUM6.5In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for t...
CVE-2025-2491MEDIUM5.4A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the...
CVE-2025-25590MEDIUM6.1yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressD...
CVE-2025-25580MEDIUM6.1yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml...
CVE-2025-2490MEDIUM5.4A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the functi...
CVE-2025-2495MEDIUM5.4Stored Cross-Site Scripting (XSS) in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to uplo...
CVE-2025-2489MEDIUM6.8Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow a...
CVE-2025-0694MEDIUM6.6Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesy...
CVE-2025-2420MEDIUM5.3A vulnerability classified as problematic was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. Affec...
CVE-2025-29781MEDIUM6.5The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator en...
CVE-2025-2397MEDIUM4.8A vulnerability was found in China Mobile P22g-CIac, ZXWT-MIG-P4G4V, ZXWT-MIG-P8G8V, GT3200-4G4P and GT3200-8G8P up to 2...
CVE-2025-2393MEDIUM5.1A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1....
CVE-2025-29426MEDIUM4.6Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.p...
CVE-2025-26393MEDIUM5.4SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to es...
CVE-2025-24185MEDIUM5.5An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, ma...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now