2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-26360MEDIUM5.3A CWE-306 "Missing Authentication for Critical Function" in maxprofile/persistance/routes.lua in Q-Free MaxTime less tha...
CVE-2025-26358MEDIUM5.5A CWE-15 "External Control of System or Configuration Setting" in ldbMT.so in Q-Free MaxTime less than or equal to versi...
CVE-2025-26357MEDIUM4.9A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 al...
CVE-2025-26355MEDIUM6.5A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 al...
CVE-2025-26353MEDIUM4.9A CWE-35 "Path Traversal" in maxtime/api/sql/sql.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an au...
CVE-2025-26352MEDIUM6.5A CWE-35 "Path Traversal" in the template deletion mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allo...
CVE-2025-26351MEDIUM4.9A CWE-35 "Path Traversal" in the template download mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allo...
CVE-2025-21699MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gfs2: Truncate address space when flipping GFS2_DIF...
CVE-2025-21697MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Ensure job pointer is set to NULL after jo...
CVE-2025-21696MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm: clear uffd-wp PTE/PMD state on mremap() When m...
CVE-2025-21695MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-uart-backlight: fix serdev race ...
CVE-2025-21694MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix softlockup in __read_vmcore (part 2) ...
CVE-2025-1201MEDIUM6.5A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been rated as critical. This iss...
CVE-2025-1101MEDIUM5.3A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 all...
CVE-2025-1199MEDIUM6.5A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been classified as critical. Thi...
CVE-2025-1196MEDIUM5.4A vulnerability, which was classified as problematic, was found in code-projects Real Estate Property Management System ...
CVE-2025-1195MEDIUM5.4A vulnerability, which was classified as problematic, has been found in code-projects Real Estate Property Management Sy...
CVE-2025-0511MEDIUM6.1The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all...
CVE-2025-1230MEDIUM4.8Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input ...
CVE-2025-1190MEDIUM6.1A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability af...
CVE-2025-0506MEDIUM5.4The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2025-0808MEDIUM5.4The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-25529MEDIUM5.1Buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is r...
CVE-2025-25528MEDIUM5.1Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict ...
CVE-2025-25527MEDIUM5.1Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now