2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-63914MEDIUM6.5An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui....
CVE-2025-36112MEDIUM5.3IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1....
CVE-2025-13466MEDIUM5.5body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large n...
CVE-2025-63953MEDIUM6.5A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta...
CVE-2025-63952MEDIUM5.7A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta...
CVE-2025-63435MEDIUM4.3Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side end...
CVE-2025-63433MEDIUM4.6Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt updat...
CVE-2025-63432MEDIUM4.6Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fai...
CVE-2025-60917MEDIUM4.6A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti...
CVE-2025-60916MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti...
CVE-2025-60914MEDIUM4.6Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensit...
CVE-2025-60633MEDIUM6.5An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_Subs...
CVE-2025-60632MEDIUM6.5An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ...
CVE-2025-56423MEDIUM5.3An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attac...
CVE-2025-10554MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERI...
CVE-2025-12978MEDIUM5.4Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fa...
CVE-2025-12972MEDIUM5.3Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option i...
CVE-2025-12969MEDIUM6.5Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain c...
CVE-2025-65503MEDIUM5.5Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via...
CVE-2025-65502MEDIUM4.3Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of s...
CVE-2025-65501MEDIUM4.3Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of...
CVE-2025-65500MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-65499MEDIUM4.3Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause...
CVE-2025-65498MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...
CVE-2025-65497MEDIUM4.3NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now