2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13677MEDIUM4.9The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2...
CVE-2025-67485MEDIUM5.3mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom se...
CVE-2025-67502MEDIUM6.1Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs t...
CVE-2025-64898MEDIUM5.3ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnera...
CVE-2025-64897MEDIUM5.6ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low...
CVE-2025-61823MEDIUM6.2ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-61822MEDIUM6.2ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61821MEDIUM6.8ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity ...
CVE-2025-67496MEDIUM5.4WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below...
CVE-2025-67495MEDIUM6.1ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XS...
CVE-2025-36437MEDIUM4.3IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could ai...
CVE-2025-34425MEDIUM6.1MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext par...
CVE-2025-64896MEDIUM5.5Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Inc...
CVE-2025-66625MEDIUM4.9Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, du...
CVE-2025-9614MEDIUM6.5An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ...
CVE-2025-9613MEDIUM6.5A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insuff...
CVE-2025-9612MEDIUM5.1An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient ...
CVE-2025-65572MEDIUM6.1Cross Site Scripting (XSS) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to execute arbitrar...
CVE-2025-65300MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28...
CVE-2025-64894MEDIUM5.5DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to ap...
CVE-2025-64670MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker...
CVE-2025-64667MEDIUM5.3User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack...
CVE-2025-62631MEDIUM5.6An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all vers...
CVE-2025-62570MEDIUM5.5Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information loc...
CVE-2025-62567MEDIUM5.3Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now