2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10928MEDIUM6.3Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This is...
CVE-2025-10927MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible t...
CVE-2025-10926MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field ...
CVE-2025-61724MEDIUM5.3The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the n...
CVE-2025-58189MEDIUM5.3When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols...
CVE-2025-58186MEDIUM5.3Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By s...
CVE-2025-58185MEDIUM5.3Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-58183MEDIUM4.3tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A mal...
CVE-2025-54549MEDIUM5.9Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgra...
CVE-2025-54548MEDIUM4.3On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user...
CVE-2025-54547MEDIUM5.3On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) mult...
CVE-2025-47912MEDIUM5.3The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component ...
CVE-2025-61959MEDIUM6.9Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebR...
CVE-2025-60320MEDIUM6.7memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (...
CVE-2025-11466MEDIUM4.9Allegra DatabaseBackupBL Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote atta...
CVE-2025-61876MEDIUM5Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an aut...
CVE-2025-64100MEDIUM6.1CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4,...
CVE-2025-1549MEDIUM6.3A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user ...
CVE-2025-60898MEDIUM5.8An unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 a...
CVE-2025-60542MEDIUM6.5SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to ...
CVE-2025-54384MEDIUM6.3CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4,...
CVE-2025-12148MEDIUM6In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Ad...
CVE-2025-12147MEDIUM6In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-value...
CVE-2025-64150MEDIUM5.4A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read per...
CVE-2025-64149MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attacker...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now