2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-68268MEDIUM6.1In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
CVE-2025-68267MEDIUM6.5In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token in...
CVE-2025-68166MEDIUM6.1In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
CVE-2025-68165MEDIUM6.1In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
CVE-2025-68163MEDIUM4.8In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
CVE-2025-65427MEDIUM6.5An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not impleme...
CVE-2025-64012MEDIUM4.3InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify owners...
CVE-2025-62329MEDIUM5.6HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which ma...
CVE-2025-14432MEDIUM4.9In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC...
CVE-2025-68223MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/radeon: delete radeon_fence_process in is_signa...
CVE-2025-68214MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: timers: Fix NULL function pointer race in timer_shu...
CVE-2025-68211MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in ...
CVE-2025-65076MEDIUM6.1WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-65075MEDIUM6.5WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-14780MEDIUM6.3A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknow...
CVE-2025-14443MEDIUM6.4A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, ...
CVE-2025-13741MEDIUM4.3The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo...
CVE-2025-11220MEDIUM6.4The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Text Path widget in all...
CVE-2025-0836MEDIUM6.3Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management S...
CVE-2025-68088MEDIUM5.4Missing Authorization vulnerability in merkulove Huger for Elementor huger-elementor allows Exploiting Incorrectly Confi...
CVE-2025-68087MEDIUM5.4Missing Authorization vulnerability in merkulove Modalier for Elementor modalier-elementor allows Exploiting Incorrectly...
CVE-2025-68086MEDIUM5.4Missing Authorization vulnerability in merkulove Reformer for Elementor reformer-elementor allows Exploiting Incorrectly...
CVE-2025-68085MEDIUM5.4Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly...
CVE-2025-68084MEDIUM5.4Missing Authorization vulnerability in Nitesh Ultimate Auction ultimate-auction allows Exploiting Incorrectly Configure...
CVE-2025-68083MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now