2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64329MEDIUM5.5containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 thro...
CVE-2025-4522MEDIUM6.5The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct ...
CVE-2025-64323MEDIUM5.3kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack a...
CVE-2025-64187MEDIUM4.4OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vul...
CVE-2025-52662MEDIUM6.1A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extra...
CVE-2025-48985MEDIUM5.3A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have ...
CVE-2025-12789MEDIUM6.1A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout p...
CVE-2025-64302MEDIUM5.4Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing ...
CVE-2025-64179MEDIUM5.3lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below,...
CVE-2025-64177MEDIUM6.1ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, th...
CVE-2025-64176MEDIUM6.1ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an...
CVE-2025-11216MEDIUM6.3Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7390.54 allowed a remote attacker to perf...
CVE-2025-11215MEDIUM4.3Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds mem...
CVE-2025-11213MEDIUM6.3Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who...
CVE-2025-11212MEDIUM6.3Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who c...
CVE-2025-11210MEDIUM5.4Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced ...
CVE-2025-11208MEDIUM6.3Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a ...
CVE-2025-11207MEDIUM6.5Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform...
CVE-2025-64327MEDIUM5.3ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contai...
CVE-2025-64174MEDIUM4.8Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affecte...
CVE-2025-33110MEDIUM5.4IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2025-34247MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAc...
CVE-2025-34246MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.aja...
CVE-2025-34245MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsControl...
CVE-2025-34244MEDIUM6.5Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDevic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now