2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62372MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can...
CVE-2025-62459MEDIUM6.1Microsoft Defender Portal Spoofing Vulnerability
CVE-2025-13484MEDIUM6.1A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affe...
CVE-2025-36159MEDIUM5.5IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their ide...
CVE-2025-36158MEDIUM5.5IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from f...
CVE-2025-36153MEDIUM6.1IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated atta...
CVE-2025-55124MEDIUM6.1Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.
CVE-2025-55123MEDIUM5.4Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be a...
CVE-2025-52671MEDIUM4.3Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes ...
CVE-2025-52670MEDIUM6.5Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete...
CVE-2025-52669MEDIUM4.3Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes no...
CVE-2025-52668MEDIUM5.4Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier version...
CVE-2025-52667MEDIUM5.4Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS...
CVE-2025-48987MEDIUM6.1Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XS...
CVE-2025-35029MEDIUM5.4Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authent...
CVE-2025-55128MEDIUM6.5HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in th...
CVE-2025-55127MEDIUM5.4HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the userna...
CVE-2025-55126MEDIUM6.5HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box ...
CVE-2025-64524MEDIUM5.5cups-filters contains backends, filters, and other software required to get the cups printing service working on operati...
CVE-2025-64185MEDIUM6.9Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writ...
CVE-2025-64027MEDIUM6.1Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. ...
CVE-2025-63848MEDIUM6.1Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code ...
CVE-2025-62724MEDIUM4.3Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time...
CVE-2025-13437MEDIUM5.6When zx is invoked with --prefer-local=<path>, the CLI creates a symlink named ./node_modules pointing to <path>/node_mo...
CVE-2025-62875MEDIUM5.5An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now