2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14276MEDIUM5.6A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /...
CVE-2025-12832MEDIUM4.3IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This ma...
CVE-2025-12635MEDIUM5.4IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are af...
CVE-2025-65230MEDIUM5.4Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuratio...
CVE-2025-65229MEDIUM4.6A stored cross-site scripting (XSS) vulnerability exists in the web interface of Lyrion Music Server <= 9.0.3. An authen...
CVE-2025-65231MEDIUM6.1Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration...
CVE-2025-65804MEDIUM6.5Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corru...
CVE-2025-48608MEDIUM5.5In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check...
CVE-2025-48569MEDIUM5.5In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to lo...
CVE-2025-14259MEDIUM6.3A vulnerability was found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is some unknown functiona...
CVE-2025-65799MEDIUM4.3A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to e...
CVE-2025-65797MEDIUM6.5Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level priv...
CVE-2025-59391MEDIUM6.5A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patche...
CVE-2025-48633MEDIUM5.5In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisio...
CVE-2025-48631MEDIUM6.5In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhausti...
CVE-2025-48622MEDIUM5.5In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead...
CVE-2025-48618MEDIUM6.8In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to...
CVE-2025-48614MEDIUM4.6In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due ...
CVE-2025-48610MEDIUM5.5In __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in...
CVE-2025-48607MEDIUM5.5In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. Thi...
CVE-2025-48604MEDIUM5.5In multiple locations, there is a possible way to read files from another user due to a missing permission check. This c...
CVE-2025-48603MEDIUM5.5In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. ...
CVE-2025-48601MEDIUM5.5In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead...
CVE-2025-48600MEDIUM5.5In multiple files, there is a possible way to reveal information across users due to a missing permission check. This co...
CVE-2025-48598MEDIUM6.6In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now