2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65581MEDIUM5.3An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improp...
CVE-2025-46296MEDIUM5.4An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privile...
CVE-2025-46294MEDIUM5.3To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumerat...
CVE-2025-68116MEDIUM5.4FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site ...
CVE-2025-62862MEDIUM4.6Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4....
CVE-2025-59935MEDIUM6.5GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an una...
CVE-2025-29231MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers...
CVE-2025-68269MEDIUM5.4In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
CVE-2025-68268MEDIUM6.1In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
CVE-2025-68267MEDIUM6.5In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token in...
CVE-2025-68166MEDIUM6.1In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
CVE-2025-68165MEDIUM6.1In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
CVE-2025-68163MEDIUM4.8In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
CVE-2025-65427MEDIUM6.5An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not impleme...
CVE-2025-64012MEDIUM4.3InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify owners...
CVE-2025-62329MEDIUM5.6HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which ma...
CVE-2025-14432MEDIUM4.9In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC...
CVE-2025-68223MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/radeon: delete radeon_fence_process in is_signa...
CVE-2025-68214MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: timers: Fix NULL function pointer race in timer_shu...
CVE-2025-68211MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksm: use range-walk function to jump over holes in ...
CVE-2025-65076MEDIUM6.1WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-65075MEDIUM6.5WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser...
CVE-2025-14780MEDIUM6.3A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknow...
CVE-2025-14443MEDIUM6.4A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, ...
CVE-2025-13741MEDIUM4.3The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin fo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now