2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1726MEDIUM4.3There is a SQL injection issue in Esri ArcGIS Monitor versions 2023.0 through 2024.x on Windows and Linux that allows a ...
CVE-2025-20161MEDIUM5.1A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches...
CVE-2025-20119MEDIUM5.7A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to ove...
CVE-2025-20118MEDIUM4.4A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local...
CVE-2025-20117MEDIUM6.7A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as r...
CVE-2025-20116MEDIUM4.8A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack...
CVE-2025-0941MEDIUM5.8MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain te...
CVE-2025-25462MEDIUM5.5A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v...
CVE-2025-25827MEDIUM6.8A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and in...
CVE-2025-25818MEDIUM5.1A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML...
CVE-2025-25813MEDIUM5.1SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.
CVE-2025-25802MEDIUM5.1SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.
CVE-2025-25800MEDIUM5.3SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_sa...
CVE-2025-25799MEDIUM6SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_sa...
CVE-2025-25797MEDIUM5.1SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.
CVE-2025-25796MEDIUM5.1SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.
CVE-2025-25794MEDIUM5.1SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.
CVE-2025-25793MEDIUM5.1SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.
CVE-2025-25792MEDIUM4.4SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_wei...
CVE-2025-25791MEDIUM4.4An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute a...
CVE-2025-1249MEDIUM5.3Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly ...
CVE-2025-26925MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This is...
CVE-2025-0719MEDIUM6.1IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an...
CVE-2025-1517MEDIUM5.4The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem...
CVE-2025-0731MEDIUM6.5An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now