2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-66500MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validat...
CVE-2025-66174MEDIUM6.8There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of ...
CVE-2025-66173MEDIUM6.2There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of auth...
CVE-2025-14449MEDIUM6.4The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-fo...
CVE-2025-14267MEDIUM4.9Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows d...
CVE-2025-13754MEDIUM5.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive ...
CVE-2025-14546MEDIUM6.3Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the imprope...
CVE-2025-67846MEDIUM6.5The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches ...
CVE-2025-67845MEDIUM5.4A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows rem...
CVE-2025-67844MEDIUM4.3The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository...
CVE-2025-67842MEDIUM5.4The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HT...
CVE-2025-14910MEDIUM6.5A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon...
CVE-2025-68422MEDIUM4.3Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated use...
CVE-2025-68390MEDIUM4.9Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna...
CVE-2025-68389MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user t...
CVE-2025-68387MEDIUM6.1Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated ...
CVE-2025-68386MEDIUM4.3Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated use...
CVE-2025-68385MEDIUM6.1Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us...
CVE-2025-68279MEDIUM6.5Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the ...
CVE-2025-68388MEDIUM5.3Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excess...
CVE-2025-68384MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated...
CVE-2025-68383MEDIUM6.5Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbea...
CVE-2025-68382MEDIUM6.5Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the ...
CVE-2025-68381MEDIUM6.5Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (...
CVE-2025-13427MEDIUM6.9An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now