2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-66400MEDIUM5.3mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classna...
CVE-2025-66312MEDIUM5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66311MEDIUM5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66310MEDIUM5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66309MEDIUM6.1This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66308MEDIUM5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66307MEDIUM5.3This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create ...
CVE-2025-66306MEDIUM6.5Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerabi...
CVE-2025-66305MEDIUM4.9Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the...
CVE-2025-66303MEDIUM4.9Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified i...
CVE-2025-66302MEDIUM6.8Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CM...
CVE-2025-65622MEDIUM5.4Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user ...
CVE-2025-65621MEDIUM5.4Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes...
CVE-2025-58044MEDIUM6.1JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and ...
CVE-2025-63317MEDIUM5.4Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization ap...
CVE-2025-12756MEDIUM4.3Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user pe...
CVE-2025-65407MEDIUM6.5A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows atta...
CVE-2025-11772MEDIUM6.6A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code w...
CVE-2025-13837MEDIUM5.5When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file...
CVE-2025-13835MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc...
CVE-2025-13653MEDIUM4.3In Search Guard FLX versions from 3.1.0 up to 4.0.0 with enterprise modules being disabled, there exists an issue which ...
CVE-2025-65408MEDIUM6.5A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming M...
CVE-2025-65406MEDIUM6.5A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allow...
CVE-2025-65405MEDIUM6.5A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows ...
CVE-2025-65404MEDIUM6.5A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Deni...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now