2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-65116MEDIUM5.5Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operati...
CVE-2025-13044MEDIUM6.2IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite ar...
CVE-2025-48651MEDIUM5.5In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to impr...
CVE-2025-61166MEDIUM6.1An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted ...
CVE-2025-47374MEDIUM6.5Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
CVE-2025-14938MEDIUM5.3The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and ...
CVE-2025-15064MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-13368MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the P...
CVE-2025-68153MEDIUM6.5Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ...
CVE-2025-68152MEDIUM4.9Juju is an open source application orchestration engine that enables any application operation on any infrastructure at ...
CVE-2025-59709MEDIUM6.8An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read b...
CVE-2025-43238MEDIUM6.2An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonom...
CVE-2025-43210MEDIUM6.3An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18...
CVE-2025-66487MEDIUM6.5IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send em...
CVE-2025-66486MEDIUM6.1IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2025-66485MEDIUM5.4IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by...
CVE-2025-66484MEDIUM5.4IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to ...
CVE-2025-66483MEDIUM6.5IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authentic...
CVE-2025-36373MEDIUM6.8IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I...
CVE-2025-66442MEDIUM5.1In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occ...
CVE-2025-67807MEDIUM4.7The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumer...
CVE-2025-67806MEDIUM5.3The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumer...
CVE-2025-13535MEDIUM6.4The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Sc...
CVE-2025-71280MEDIUM5.5XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu...
CVE-2025-41357MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now