2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-25510MEDIUM6.5Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.
CVE-2025-25507MEDIUM6.5There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will...
CVE-2025-25505MEDIUM6.5Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.
CVE-2025-1548MEDIUM4.6A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affect...
CVE-2025-1544MEDIUM6.3A vulnerability, which was classified as critical, was found in dingfanzu CMS up to 20250210. Affected is an unknown fun...
CVE-2025-1543MEDIUM5.3A vulnerability, which was classified as problematic, has been found in iteachyou Dreamer CMS 4.1.3. This issue affects ...
CVE-2025-1537MEDIUM6.3A vulnerability was found in Harpia DiagSystem 12. It has been rated as critical. This issue affects some unknown proces...
CVE-2025-1489MEDIUM5.4The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all...
CVE-2025-1402MEDIUM5.3The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capa...
CVE-2025-1470MEDIUM5.5In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers o...
CVE-2025-1410MEDIUM5.4The Events Calendar Made Simple – Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-1407MEDIUM5.4The AMO Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's amoteam_skills ...
CVE-2025-1406MEDIUM5.4The Newpost Catch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's npc shortcode in al...
CVE-2025-1001MEDIUM5.7Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server's certifi...
CVE-2025-27100MEDIUM6.5lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an au...
CVE-2025-25957MEDIUM6.1Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via...
CVE-2025-25960MEDIUM6.1Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu inte...
CVE-2025-25958MEDIUM5.4Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted s...
CVE-2025-25973MEDIUM6.5A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote a...
CVE-2025-25968MEDIUM6DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged us...
CVE-2025-26311MEDIUM6.5Multiple memory leaks have been identified in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIP...
CVE-2025-26310MEDIUM6.5Multiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE)...
CVE-2025-26309MEDIUM6.5A memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, w...
CVE-2025-26308MEDIUM6.5A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows a...
CVE-2025-26307MEDIUM6.5A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allow...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now