2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65113MEDIUM6.5ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerabi...
CVE-2025-64715MEDIUM5.5Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1....
CVE-2025-13683MEDIUM6.5Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affec...
CVE-2025-59792MEDIUM5.3Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks...
CVE-2025-59790MEDIUM5.4Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v...
CVE-2025-51736MEDIUM6.3File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-51734MEDIUM5.4Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-51733MEDIUM5.5Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.
CVE-2025-11156MEDIUM5.9Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully ex...
CVE-2025-12143MEDIUM6.9Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.
CVE-2025-66386MEDIUM4.1app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.
CVE-2025-66382MEDIUM5.5In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing ...
CVE-2025-66371MEDIUM5Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XM...
CVE-2025-66370MEDIUM5Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to...
CVE-2025-58305MEDIUM5.5Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability m...
CVE-2025-58304MEDIUM5.5Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma...
CVE-2025-58302MEDIUM5.5Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2025-13737MEDIUM4.3The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2025-64314MEDIUM5.5Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability ...
CVE-2025-64313MEDIUM5.5Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may a...
CVE-2025-64311MEDIUM5.5Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect...
CVE-2025-58316MEDIUM5.5DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may ...
CVE-2025-58315MEDIUM5.5Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2025-58312MEDIUM5.5Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affec...
CVE-2025-58310MEDIUM5.5Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now