2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-15118MEDIUM4.3A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of th...
CVE-2025-15116MEDIUM4.8A security flaw has been discovered in OpenCart up to 4.1.0.3. Affected by this issue is some unknown functionality of t...
CVE-2025-68972MEDIUM4.7In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified...
CVE-2025-15106MEDIUM4.3A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi...
CVE-2025-15105MEDIUM5.9A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxu...
CVE-2025-68927MEDIUM6.1Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML in...
CVE-2025-68697MEDIUM5.4n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code ...
CVE-2025-61914MEDIUM5.4n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulner...
CVE-2025-66737MEDIUM4.3Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbi...
CVE-2025-67013MEDIUM6.5The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not impleme...
CVE-2025-67349MEDIUM6.1A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigatin...
CVE-2025-66947MEDIUM6.5SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editi...
CVE-2025-65885MEDIUM5.1An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8)...
CVE-2025-36230MEDIUM5.4IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTM...
CVE-2025-36229MEDIUM4.3IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data du...
CVE-2025-14687MEDIUM6.5IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to...
CVE-2025-59888MEDIUM6.7Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution ...
CVE-2025-8075MEDIUM5.4Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-68946MEDIUM5.4In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
CVE-2025-52599MEDIUM6.5Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/Io...
CVE-2025-68945MEDIUM5.3In Gitea before 1.21.2, an anonymous user can visit a private user's project.
CVE-2025-68944MEDIUM5.3Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package...
CVE-2025-68943MEDIUM5.3Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users...
CVE-2025-68942MEDIUM5.4Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text...
CVE-2025-68941MEDIUM5.3Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public res...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now