2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-66265MEDIUM6.9CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all a...
CVE-2025-66260MEDIUM6.5PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, ...
CVE-2025-66258MEDIUM5.4Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions ...
CVE-2025-66019MEDIUM6.6pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability...
CVE-2025-65963MEDIUM5.4Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient...
CVE-2025-65956MEDIUM5.4Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into t...
CVE-2025-65953MEDIUM6NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UA...
CVE-2025-64704MEDIUM5.5WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is...
CVE-2025-63735MEDIUM6.1A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the th...
CVE-2025-21621MEDIUM6.1GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a refle...
CVE-2025-65647MEDIUM4.3Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows info...
CVE-2025-65961MEDIUM4.8Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to i...
CVE-2025-65960MEDIUM6.6Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with...
CVE-2025-64067MEDIUM5.3Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles...
CVE-2025-61167MEDIUM6.5SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php c...
CVE-2025-33197MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereferen...
CVE-2025-33196MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused....
CVE-2025-33193MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of i...
CVE-2025-33192MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read...
CVE-2025-33191MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read....
CVE-2025-64061MEDIUM4.3Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access con...
CVE-2025-64049MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote ...
CVE-2025-13467MEDIUM5.5A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm adminis...
CVE-2025-59485MEDIUM4.8Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerabili...
CVE-2025-59372MEDIUM6.9A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could expl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now