2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-63432MEDIUM4.6Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fai...
CVE-2025-60917MEDIUM4.6A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti...
CVE-2025-60916MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti...
CVE-2025-60914MEDIUM4.6Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensit...
CVE-2025-60633MEDIUM6.5An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_Subs...
CVE-2025-60632MEDIUM6.5An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ...
CVE-2025-56423MEDIUM5.3An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attac...
CVE-2025-10554MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERI...
CVE-2025-12978MEDIUM5.4Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fa...
CVE-2025-12972MEDIUM5.3Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option i...
CVE-2025-12969MEDIUM6.5Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain c...
CVE-2025-65503MEDIUM5.5Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via...
CVE-2025-65502MEDIUM4.3Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of s...
CVE-2025-65501MEDIUM4.3Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of...
CVE-2025-65500MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-65499MEDIUM4.3Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause...
CVE-2025-65498MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-65497MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-65496MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-41017MEDIUM6.9Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve pers...
CVE-2025-12628MEDIUM6.3The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass th...
CVE-2025-41087MEDIUM5.1Cross-Site Scripting (XSS) vulnerability stored in tha Taclia web application, where the uploaded SVG images are not pro...
CVE-2025-13588MEDIUM6.3A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown fun...
CVE-2025-12569MEDIUM4.7The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before ...
CVE-2025-12394MEDIUM5.9The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configur...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now