2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30431MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Vent...
CVE-2025-24268MEDIUM5.5A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m...
CVE-2025-24165MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma ...
CVE-2025-7064MEDIUM6.6Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2...
CVE-2025-8444MEDIUM6.4The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerabl...
CVE-2025-62851MEDIUM4.4A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator ac...
CVE-2025-55659MEDIUM6.5A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attacker...
CVE-2025-55658MEDIUM6.5GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media...
CVE-2025-55651MEDIUM5.5A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows...
CVE-2025-54509MEDIUM4Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileg...
CVE-2025-67862MEDIUM6.7An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti...
CVE-2025-40808MEDIUM6.9A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),...
CVE-2025-62858MEDIUM6.5A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker...
CVE-2025-71315MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vk...
CVE-2025-65640MEDIUM6.3Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5....
CVE-2025-52611MEDIUM4.3HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to ...
CVE-2025-52609MEDIUM5.3HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by...
CVE-2025-52608MEDIUM4.3HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing s...
CVE-2025-52606MEDIUM4.3HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an ar...
CVE-2025-71314MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Recover from panthor_gpu_flush_caches(...
CVE-2025-71313MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Add missing NULL check for alloc_wor...
CVE-2025-70101MEDIUM6.5An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows att...
CVE-2025-70100MEDIUM5.5A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library...
CVE-2025-60477MEDIUM5A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Pr...
CVE-2025-14773MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. T...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now