2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36889MEDIUM5.5In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy. This could lead...
CVE-2025-13211MEDIUM6.5IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email ...
CVE-2025-13148MEDIUM6.5IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another us...
CVE-2025-14531MEDIUM4.3A vulnerability was found in code-projects Rental Management System 2.0. This affects an unknown function of the file Tr...
CVE-2025-14046MEDIUM6.1An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied ...
CVE-2025-67741MEDIUM5.4In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
CVE-2025-67740MEDIUM5.3In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
CVE-2025-59803MEDIUM5.3Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via triggers. An attacker can embed triggers (e.g.,...
CVE-2025-55311MEDIUM6.5An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF ...
CVE-2025-55309MEDIUM6.7An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF ...
CVE-2025-55308MEDIUM6.7An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing...
CVE-2025-14519MEDIUM5.4A security flaw has been discovered in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. This issue affects so...
CVE-2025-14517MEDIUM5.3A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity  of the file AndroidMan...
CVE-2025-64995MEDIUM6.7A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Exchan...
CVE-2025-64994MEDIUM6.7A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-...
CVE-2025-46266MEDIUM6.5A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi...
CVE-2025-12687MEDIUM6.5A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi...
CVE-2025-14512MEDIUM6.5A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer ov...
CVE-2025-4097MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and ...
CVE-2025-11984MEDIUM6.8GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 1...
CVE-2025-11247MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6...
CVE-2025-9436MEDIUM6.4The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `trust...
CVE-2025-14157MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18...
CVE-2025-13978MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 1...
CVE-2025-10163MEDIUM6.5The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ parameter...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now