2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64435MEDIUM5.3KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controll...
CVE-2025-64434MEDIUM6.3KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification l...
CVE-2025-64433MEDIUM6.5KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered...
CVE-2025-63420MEDIUM4.1CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created F...
CVE-2025-12418MEDIUM5.6Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2,...
CVE-2025-64442MEDIUM6.1HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search fe...
CVE-2025-63544MEDIUM6.1TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter.
CVE-2025-63543MEDIUM6.1TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter.
CVE-2025-12902MEDIUM4.4Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical acces...
CVE-2025-12896MEDIUM4.4Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical acces...
CVE-2025-63640MEDIUM6.1Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes ...
CVE-2025-63639MEDIUM6.1The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting ...
CVE-2025-63638MEDIUM6.1Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Descr...
CVE-2025-7700MEDIUM5.3A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This ca...
CVE-2025-64432MEDIUM4.7KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed i...
CVE-2025-63717MEDIUM6.5The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Softw...
CVE-2025-61261MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute a...
CVE-2025-36185MEDIUM5.5IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to caus...
CVE-2025-36136MEDIUM5.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could...
CVE-2025-36135MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gatewa...
CVE-2025-36131MEDIUM4.6IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ...
CVE-2025-36008MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2025-36006MEDIUM6.5IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNI...
CVE-2025-12890MEDIUM6.5Improper handling of malformed Connection Request with the interval set to be 1 (which supposed to be illegal) and the ...
CVE-2025-63718MEDIUM6.5A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now