2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61822MEDIUM6.2ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61821MEDIUM6.8ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-67496MEDIUM5.4WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below...
CVE-2025-67495MEDIUM6.1ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XS...
CVE-2025-36437MEDIUM4.3IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could ai...
CVE-2025-34425MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext par...
CVE-2025-64896MEDIUM5.5Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Inc...
CVE-2025-66625MEDIUM4.9Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, du...
CVE-2025-9614MEDIUM6.5An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ...
CVE-2025-9613MEDIUM6.5A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insuff...
CVE-2025-9612MEDIUM5.1An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ...
CVE-2025-65572MEDIUM6.1Cross Site Scripting (XSS) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to execute arbitrar...
CVE-2025-65300MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28...
CVE-2025-64894MEDIUM5.5DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to ap...
CVE-2025-64670MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker...
CVE-2025-64667MEDIUM5.3User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack...
CVE-2025-62631MEDIUM5.6An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all vers...
CVE-2025-62570MEDIUM5.5Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information loc...
CVE-2025-62567MEDIUM5.3Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.
CVE-2025-62473MEDIUM6.5Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa...
CVE-2025-62468MEDIUM5.5Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
CVE-2025-62465MEDIUM6.5Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
CVE-2025-62463MEDIUM6.5Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
CVE-2025-61078MEDIUM6.1Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrar...
CVE-2025-59810MEDIUM6.5An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now