2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59853MEDIUM5.3HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack tr...
CVE-2025-31970MEDIUM6.1HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Polic...
CVE-2025-61669MEDIUM6.1Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query pa...
CVE-2025-52206MEDIUM4.7ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
CVE-2025-42611MEDIUM6.5RouterOS provides various services that rely on correct verification of client and server certificates to secure confide...
CVE-2025-47406MEDIUM5.5Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
CVE-2025-70071MEDIUM5.9An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataA...
CVE-2025-70072MEDIUM6.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter:...
CVE-2025-70070MEDIUM6.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeomet...
CVE-2025-14726MEDIUM6.5The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of ...
CVE-2025-69606MEDIUM6.1Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in t...
CVE-2025-36335MEDIUM5.5IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a lo...
CVE-2025-36122MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could...
CVE-2025-14688MEDIUM5.3IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2025-56537MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute...
CVE-2025-56536MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri...
CVE-2025-56535MEDIUM6.1A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or ...
CVE-2025-56534MEDIUM6.1A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t...
CVE-2025-10503MEDIUM6.1The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a ...
CVE-2025-60887MEDIUM5.3An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions m...
CVE-2025-10539MEDIUM4.8Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p...
CVE-2025-15626MEDIUM5.3Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application
CVE-2025-67259MEDIUM6.5A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user...
CVE-2025-59308MEDIUM4.7In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a ...
CVE-2025-61872MEDIUM6.1Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search quer...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now