2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54125MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ...
CVE-2025-54124MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ...
CVE-2025-32430MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2...
CVE-2025-8573MEDIUM4.8Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.  Version ...
CVE-2025-8571MEDIUM4.8Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversa...
CVE-2025-53534HIGH7.7RatPanel is a server operation and maintenance management panel. In versions 2.3.19 through 2.5.5, when an attacker obta...
CVE-2025-52237MEDIUM6.5An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory travers...
CVE-2025-52078MEDIUM6.5File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to ...
CVE-2025-51541MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/d...
CVE-2025-50592MEDIUM5.4Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
CVE-2025-45512MEDIUM6.5A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attack...
CVE-2025-8586LOW3.3A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_f...
CVE-2025-51857MEDIUM6.1The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS a...
CVE-2025-51628HIGH7.5Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and be...
CVE-2025-51627MEDIUM6.5Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-le...
CVE-2025-51060MEDIUM6.5An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0...
CVE-2025-50688MEDIUM6.5A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file u...
CVE-2025-50454MEDIUM6.5An Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an unauthorized attacker to log ...
CVE-2025-8585MEDIUM5.3A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the fun...
CVE-2025-8584LOW3.3A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function ...
CVE-2025-7674HIGH7.1Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input da...
CVE-2025-54254HIGH8.6Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Refe...
CVE-2025-54253CRITICAL10Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result ...
CVE-2025-43980MEDIUM6.5An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN. They enable the SSH service by default with the ...
CVE-2025-43978HIGH7.4Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now