2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64730MEDIUM6.1Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary s...
CVE-2025-64304MEDIUM5.1"FOD" App uses hard-coded cryptographic keys, which may allow a local unauthenticated attacker to retrieve the cryptogra...
CVE-2025-62497MEDIUM6.5Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a speciall...
CVE-2025-13558MEDIUM5.4The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2025-12893MEDIUM5.4Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not align...
CVE-2025-10646MEDIUM4.3The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capabil...
CVE-2025-65944MEDIUM5.1Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js appl...
CVE-2025-64506MEDIUM6.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-64505MEDIUM6.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2025-10144MEDIUM6.5The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri...
CVE-2025-63674MEDIUM6.8An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary c...
CVE-2025-54341MEDIUM5.3A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Ha...
CVE-2025-63498MEDIUM6.1alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.
CVE-2025-48511MEDIUM5.5Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potenti...
CVE-2025-29933MEDIUM5.5Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a...
CVE-2025-0007MEDIUM5.7Insufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user s...
CVE-2025-64048MEDIUM6.1YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulner...
CVE-2025-64047MEDIUM6.1OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.
CVE-2025-63914MEDIUM6.5An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui....
CVE-2025-36112MEDIUM5.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1....
CVE-2025-13466MEDIUM5.5body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large n...
CVE-2025-63953MEDIUM6.5A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta...
CVE-2025-63952MEDIUM5.7A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta...
CVE-2025-63435MEDIUM4.3Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side end...
CVE-2025-63433MEDIUM4.6Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt updat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now