2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67780MEDIUM4.2SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via un...
CVE-2025-66452MEDIUM6.1LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing...
CVE-2025-66451MEDIUM6.5LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests...
CVE-2025-66450MEDIUM5.4LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the ic...
CVE-2025-34504MEDIUM6.1KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the ...
CVE-2025-34499MEDIUM6.9AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to poten...
CVE-2025-13668MEDIUM6.7A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege.
CVE-2025-64702MEDIUM5.3quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory al...
CVE-2025-55816MEDIUM6.1HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.
CVE-2025-14293MEDIUM6.5The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 ...
CVE-2025-13664MEDIUM6.7A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege.
CVE-2025-13663MEDIUM6.7Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus t...
CVE-2025-55183MEDIUM5.3An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 1...
CVE-2025-36938MEDIUM6.8In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead t...
CVE-2025-36929MEDIUM5.5In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. T...
CVE-2025-36922MEDIUM6.7In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to loc...
CVE-2025-36921MEDIUM5.5In ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds ch...
CVE-2025-36917MEDIUM6.5In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrect bounds check. This...
CVE-2025-36912MEDIUM6.5In cellular modem, there is a possible denial of service due to a logic error in the code. This could lead to remote den...
CVE-2025-36889MEDIUM5.5In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy. This could lead...
CVE-2025-13211MEDIUM6.5IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email ...
CVE-2025-13148MEDIUM6.5IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another us...
CVE-2025-14531MEDIUM4.3A vulnerability was found in code-projects Rental Management System 2.0. This affects an unknown function of the file Tr...
CVE-2025-14046MEDIUM6.1An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied ...
CVE-2025-67741MEDIUM5.4In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now