2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-56761MEDIUM5.4Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar f...
CVE-2025-56760MEDIUM4.3When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint co...
CVE-2025-56689MEDIUM4.6One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/...
CVE-2025-9920HIGH7.2A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of...
CVE-2025-9919CRITICAL9.8A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of...
CVE-2025-56498MEDIUM5.3An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interf...
CVE-2025-56435MEDIUM5.3SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file...
CVE-2025-55944MEDIUM6.1Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a n...
CVE-2025-55852HIGH7.5Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or s...
CVE-2025-48876Rejected reason: This CVE is a duplicate of another CVE.
CVE-2025-0280HIGH7.5A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
CVE-2025-9824MEDIUM5.9ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used ...
CVE-2025-9823MEDIUM4.8SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of a...
CVE-2025-58644HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes...
CVE-2025-58643HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-q...
CVE-2025-58642HIGH7.2Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition ltl-freight...
CVE-2025-58641MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in kamleshyadav Exit Intent Popup exitintentpopup allows Server Side Re...
CVE-2025-58640MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MatrixAddons Docum...
CVE-2025-58639MEDIUM5.4Missing Authorization vulnerability in Ali Khallad Contact Form By Mega Forms mega-forms allows Exploiting Incorrectly C...
CVE-2025-58637HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-58635MEDIUM5.3Missing Authorization vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configure...
CVE-2025-58634MEDIUM5.3Missing Authorization vulnerability in peachpay PeachPay Payments peachpay-for-woocommerce allows Exploiting Incorrectly...
CVE-2025-58633MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking ...
CVE-2025-58632MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dadevarzan Dadevar...
CVE-2025-58631MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZEEN101 IssueM iss...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now