2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1390MEDIUM6.1The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configu...
CVE-2025-25223MEDIUM5.3The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal v...
CVE-2025-25055MEDIUM5.3Authentication bypass by spoofing issue exists in FileMegane versions above 1.0.0.0 prior to 3.4.0.0, which may lead to ...
CVE-2025-1392MEDIUM5.4A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is...
CVE-2025-1391MEDIUM5.4A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a use...
CVE-2025-26778MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Gallery...
CVE-2025-26775MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR wo...
CVE-2025-26772MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit...
CVE-2025-26771MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT B...
CVE-2025-26770MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Waymark waymar...
CVE-2025-26769MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilia Inc. Verte...
CVE-2025-26758MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social M...
CVE-2025-26754MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Timeline ...
CVE-2025-0714MEDIUM6.5The vulnerability exists in the password storage of Mobateks MobaXterm in versions below 25.0. MobaXTerm uses an initial...
CVE-2025-0001MEDIUM6.5Abacus ERP is versions older than 2024.210.16036, 2023.205.15833, 2022.105.15542 are affected by an authenticated arbitr...
CVE-2025-1378MEDIUM4.8A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function ...
CVE-2025-1377MEDIUM5.5A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the funct...
CVE-2025-1376MEDIUM4.7A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_s...
CVE-2025-0924MEDIUM6.1The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all...
CVE-2025-1373MEDIUM5.5A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function ...
CVE-2025-26700MEDIUM5.2Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android ver...
CVE-2025-1371MEDIUM5.5A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the funct...
CVE-2025-1370MEDIUM5.3A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affecte...
CVE-2025-1369MEDIUM4.5A vulnerability classified as critical was found in MicroWord eScan Antivirus 7.0.32 on Linux. Affected by this vulnerab...
CVE-2025-1368MEDIUM4.6A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulner...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now