2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-23118MEDIUM6.4An Improper Certificate Validation vulnerability could allow an authenticated malicious actor with access to UniFi Prote...
CVE-2025-23117MEDIUM6.8An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious actor with access to Uni...
CVE-2025-27416MEDIUM5.9Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with ...
CVE-2025-25478MEDIUM6.5The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mi...
CVE-2025-25476MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to e...
CVE-2025-26466MEDIUM5.9A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a m...
CVE-2025-27414MEDIUM4.6MinIO is a high performance object storage. Starting in RELEASE.2024-06-06T09-36-42Z and prior to RELEASE.2025-02-28T09...
CVE-2025-27413MEDIUM4.9PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an a...
CVE-2025-27410MEDIUM6.5PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerab...
CVE-2025-0769MEDIUM6.3PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is us...
CVE-2025-25429MEDIUM4.8Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside t...
CVE-2025-27408MEDIUM4.8Manifest offers users a one-file micro back end. Prior to version 4.9.2, Manifest employs a weak password hashing implem...
CVE-2025-25431MEDIUM4.8Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_dat...
CVE-2025-25430MEDIUM4.8Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on ...
CVE-2025-24843MEDIUM5.1Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confide...
CVE-2025-24318MEDIUM6.8Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromi...
CVE-2025-24316MEDIUM6.9The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, ...
CVE-2025-23405MEDIUM6.9Unauthenticated log effects metrics gathering incident response efforts and potentially exposes risk of injection attack...
CVE-2025-0985MEDIUM5.5IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD stores potentially sensitive information in environment variables that cou...
CVE-2025-26263MEDIUM5.1GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred...
CVE-2025-26047MEDIUM5.1Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.
CVE-2025-25461MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category...
CVE-2025-25916MEDIUM5.4wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.
CVE-2025-1776MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to exe...
CVE-2025-1749MEDIUM4.7HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to mod...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now