2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-51733MEDIUM5.5Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-11156MEDIUM5.9Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully ex...
CVE-2025-12143MEDIUM6.9Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.
CVE-2025-66386MEDIUM4.1app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.
CVE-2025-66382MEDIUM5.5In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing ...
CVE-2025-66371MEDIUM5Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XM...
CVE-2025-66370MEDIUM5Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to...
CVE-2025-58305MEDIUM5.5Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability m...
CVE-2025-58304MEDIUM5.5Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma...
CVE-2025-58302MEDIUM5.5Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2025-13737MEDIUM4.3The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2025-64314MEDIUM5.5Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability ...
CVE-2025-64313MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may a...
CVE-2025-64311MEDIUM5.5Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect...
CVE-2025-58316MEDIUM5.5DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-58315MEDIUM5.5Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2025-58312MEDIUM5.5Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2025-58310MEDIUM5.5Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may...
CVE-2025-58307MEDIUM5.5UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af...
CVE-2025-58303MEDIUM5.5UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af...
CVE-2025-58294MEDIUM5.5Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2025-66361MEDIUM6.5An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended p...
CVE-2025-66359MEDIUM6.1An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multipl...
CVE-2025-12559MEDIUM4.3Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team em...
CVE-2025-13765MEDIUM4.3Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects De...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now