2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-13674MEDIUM5.5BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
CVE-2025-62728MEDIUM5.4SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thr...
CVE-2025-59820MEDIUM6.7In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex...
CVE-2025-66026MEDIUM6.1REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the M...
CVE-2025-66025MEDIUM4.3Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page i...
CVE-2025-66021MEDIUM6.1OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by thir...
CVE-2025-12848MEDIUM6.1Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name ...
CVE-2025-66265MEDIUM6.9CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all a...
CVE-2025-66260MEDIUM6.5PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, ...
CVE-2025-66258MEDIUM5.4Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions ...
CVE-2025-66019MEDIUM6.6pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability...
CVE-2025-65963MEDIUM5.4Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient...
CVE-2025-65956MEDIUM5.4Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into t...
CVE-2025-65953MEDIUM6NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UA...
CVE-2025-64704MEDIUM5.5WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is...
CVE-2025-63735MEDIUM6.1A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the th...
CVE-2025-21621MEDIUM6.1GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a refle...
CVE-2025-65647MEDIUM4.3Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows info...
CVE-2025-65961MEDIUM4.8Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to i...
CVE-2025-65960MEDIUM6.6Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with...
CVE-2025-64067MEDIUM5.3Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles...
CVE-2025-61167MEDIUM6.5SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php c...
CVE-2025-33197MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereferen...
CVE-2025-33196MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused....
CVE-2025-33193MEDIUM5.5NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now