2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-68940MEDIUM5.3In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
CVE-2025-68939MEDIUM5.3Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via...
CVE-2025-15098MEDIUM6.3A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/Bpm...
CVE-2025-68938MEDIUM5.3Gitea before 1.25.2 mishandles authorization for deletion of releases.
CVE-2025-15094MEDIUM6.1A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element ...
CVE-2025-15093MEDIUM6.1A security flaw has been discovered in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The affected ele...
CVE-2025-14913MEDIUM5.3The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unau...
CVE-2025-15088MEDIUM6.3A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.lo...
CVE-2025-15087MEDIUM4.3A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPa...
CVE-2025-15086MEDIUM4.3A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the...
CVE-2025-68936MEDIUM6.1ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
CVE-2025-68935MEDIUM6.1ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to D...
CVE-2025-15083MEDIUM4.6A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the componen...
CVE-2025-15081MEDIUM6.3A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdc...
CVE-2025-66443MEDIUM5.3Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improp...
CVE-2025-49088MEDIUM5.9Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join...
CVE-2025-68919MEDIUM5.6Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when ...
CVE-2025-68917MEDIUM6.4ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.
CVE-2025-68915MEDIUM4.8Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.
CVE-2025-68914MEDIUM5.3Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker ...
CVE-2025-36154MEDIUM6.2IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be ...
CVE-2025-60935MEDIUM6.1An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malici...
CVE-2025-2154MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call C...
CVE-2025-68749MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix race condition when unbinding BOs ...
CVE-2025-68606MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post al...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now