2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13755MEDIUM5.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) store...
CVE-2025-62745MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team S...
CVE-2025-46371MEDIUM5.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability ...
CVE-2025-32751MEDIUM5.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. A low...
CVE-2025-32746MEDIUM5.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An un...
CVE-2025-32745MEDIUM6.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificate Validation vulnerability. An unauthentica...
CVE-2025-31985MEDIUM6.5HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Ty...
CVE-2025-15369MEDIUM5.3The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due...
CVE-2025-15645MEDIUM5.1Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t...
CVE-2025-57798MEDIUM5.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.1...
CVE-2025-40904MEDIUM5.4A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an...
CVE-2025-40903MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper valid...
CVE-2025-40902MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input p...
CVE-2025-40901MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation...
CVE-2025-40900MEDIUM5.1An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an...
CVE-2025-65954MEDIUM6.1SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions bel...
CVE-2025-4202MEDIUM4.3The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized mo...
CVE-2025-67031MEDIUM6.3ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnera...
CVE-2025-67437MEDIUM6.5Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows a...
CVE-2025-14972MEDIUM4.1* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually...
CVE-2025-66664MEDIUM4.6Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malf...
CVE-2025-54511MEDIUM5.3Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an inp...
CVE-2025-48516MEDIUM6.9Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with loc...
CVE-2025-48513MEDIUM6.9Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini...
CVE-2025-29944MEDIUM6.8A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now