2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53346MEDIUM4.3Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2025-53302MEDIUM5.3Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constraine...
CVE-2025-52766MEDIUM6.5Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access ...
CVE-2025-5085MEDIUM5.5The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in al...
CVE-2025-59614MEDIUM6.7Memory Corruption when sending random number generator command with insufficient output buffer size.
CVE-2025-59613MEDIUM6.7Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
CVE-2025-59612MEDIUM6.7Memory corruption in windows drivers while sending incorrect trusted application request
CVE-2025-59611MEDIUM6.7Memory corruption in diagnostic services due to absence of input validation
CVE-2025-59610MEDIUM6.4Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-spa...
CVE-2025-59609MEDIUM5.5Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
CVE-2025-59601MEDIUM6.5Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized...
CVE-2025-48648MEDIUM5.5In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This cou...
CVE-2025-60495MEDIUM5.5A segmentation violation in the gf_media_get_color_info function (/media_tools/isom_tools.c) of GPAC Project/MP4Box befo...
CVE-2025-60486MEDIUM5.5A heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows at...
CVE-2025-60485MEDIUM5.5A segmentation violation in the gf_isom_apple_set_tag_ex function (/isomedia/isom_write.c) of GPAC Project/MP4Box before...
CVE-2025-60483MEDIUM5.5A NULL pointer dereference in the gf_ac4_pres_b_4_back_channels_present function (/media_tools/av_parsers.c) of GPAC Pro...
CVE-2025-60481MEDIUM5.5A NULL pointer dereference in the gf_odf_ac4_cfg_dsi_v1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.0...
CVE-2025-55664MEDIUM5.5A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to ...
CVE-2025-12714MEDIUM5.3The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due ...
CVE-2025-14042MEDIUM6.4The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-48977MEDIUM6.5Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the ...
CVE-2025-67903MEDIUM5.3Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
CVE-2025-70116MEDIUM4.3A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can r...
CVE-2025-68712MEDIUM5.5SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerp...
CVE-2025-71312MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now