2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-12518MEDIUM5.3beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder functionality. Malicious ...
CVE-2025-15363MEDIUM5.9The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as c...
CVE-2025-14806MEDIUM5.7IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing an...
CVE-2025-15584MEDIUM6.8Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe...
CVE-2025-13406MEDIUM6.8NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows ...
CVE-2025-62320MEDIUM6.1HTML Injection can be carried out in Product when a web application does not properly check or clean user input before s...
CVE-2025-71239MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: audit: add fchmodat2() to change attributes class ...
CVE-2025-69693MEDIUM5.4Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) va...
CVE-2025-68971MEDIUM6.5In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attach...
CVE-2025-69727MEDIUM5.3An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (...
CVE-2025-69196MEDIUM6.5FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly r...
CVE-2025-65734MEDIUM5.4An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, ...
CVE-2025-57543MEDIUM6.1Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitra...
CVE-2025-52649MEDIUM5.3HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers ...
CVE-2025-52646MEDIUM5.3HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu...
CVE-2025-52645MEDIUM5.3HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient aut...
CVE-2025-52642MEDIUM6.5HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or ...
CVE-2025-2274MEDIUM6.1Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Store...
CVE-2025-71264MEDIUM5.3Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).
CVE-2025-6969MEDIUM5.5in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
CVE-2025-69245MEDIUM6.1Raytha CMS is vulnerable to Reflected XSS via returnUrl parameter in logon functionality. An attacker can craft a malici...
CVE-2025-69243MEDIUM5.3Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in messages could allow an atta...
CVE-2025-69242MEDIUM6.1Raytha CMS is vulnerable to reflected XSS via the backToListUrl parameter. An attacker can craft a malicious URL which, ...
CVE-2025-69241MEDIUM5.4Raytha CMS is vulnerable to Stored XSS via FirstName and LastName parameters in profile editing functionality. Authentic...
CVE-2025-69238MEDIUM4.3Raytha CMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. Attacker can craft special website, wh...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now