2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67740MEDIUM5.3In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
CVE-2025-59803MEDIUM5.3Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g.,...
CVE-2025-55311MEDIUM6.5An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF ...
CVE-2025-55309MEDIUM6.7An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF ...
CVE-2025-55308MEDIUM6.7An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing...
CVE-2025-14519MEDIUM5.4A security flaw has been discovered in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. This issue affects so...
CVE-2025-14517MEDIUM5.3A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity  of the file AndroidMan...
CVE-2025-64995MEDIUM6.7A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchan...
CVE-2025-64994MEDIUM6.7A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-...
CVE-2025-46266MEDIUM6.5A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi...
CVE-2025-12687MEDIUM6.5A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi...
CVE-2025-14512MEDIUM6.5A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer ov...
CVE-2025-4097MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and ...
CVE-2025-11984MEDIUM6.8GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 1...
CVE-2025-11247MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6...
CVE-2025-9436MEDIUM6.4The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `trust...
CVE-2025-14157MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18...
CVE-2025-13978MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 1...
CVE-2025-10163MEDIUM6.5The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ parameter...
CVE-2025-14485MEDIUM5A weakness has been identified in EFM ipTIME A3004T 14.19.0. This vulnerability affects the function show_debug_screen o...
CVE-2025-11467MEDIUM5.8The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2025-67720MEDIUM6.5Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames...
CVE-2025-67717MEDIUM4.3ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 discl...
CVE-2025-67716MEDIUM5.7The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through ...
CVE-2025-67713MEDIUM6.1Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now