2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-70072MEDIUM6.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter:...
CVE-2025-70070MEDIUM6.5An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeomet...
CVE-2025-14726MEDIUM6.5The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of ...
CVE-2025-69606MEDIUM6.1Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in t...
CVE-2025-36335MEDIUM5.5IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 stores user credentials in plain text which can be read by a lo...
CVE-2025-36122MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could...
CVE-2025-14688MEDIUM5.3IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2025-56537MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute...
CVE-2025-56536MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scri...
CVE-2025-56535MEDIUM6.1A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or ...
CVE-2025-56534MEDIUM6.1A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers t...
CVE-2025-10503MEDIUM6.1The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a ...
CVE-2025-60887MEDIUM5.3An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions m...
CVE-2025-10539MEDIUM4.8Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can p...
CVE-2025-15626MEDIUM5.3Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application
CVE-2025-67259MEDIUM6.5A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user...
CVE-2025-59308MEDIUM4.7In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a ...
CVE-2025-61872MEDIUM6.1Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search quer...
CVE-2025-62233MEDIUM6.3Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache Dolphi...
CVE-2025-11762MEDIUM4.3The HubSpot All-In-One Marketing - Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2025-66286MEDIUM4.7An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS ...
CVE-2025-13763MEDIUM5.7Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application ...
CVE-2025-62110MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Resc...
CVE-2025-62104MEDIUM4.3Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Con...
CVE-2025-10549MEDIUM5.1EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now