2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-69237MEDIUM5.4Raytha CMS is vulnerable to Stored XSS via FieldValues[0].Value parameter in page creation functionality. Authenticated ...
CVE-2025-69236MEDIUM5.4Raytha CMS is vulnerable to Stored XSS via FieldValues[1].Value parameter in post editing functionality. Authenticated a...
CVE-2025-13460MEDIUM5.3IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response disc...
CVE-2025-13459MEDIUM4.9IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforc...
CVE-2025-13212MEDIUM4.3IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email servi...
CVE-2025-12736MEDIUM6.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitial...
CVE-2025-10461MEDIUM5.3Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker ...
CVE-2025-8766MEDIUM6.4A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from...
CVE-2025-66249MEDIUM6.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue...
CVE-2025-60012MEDIUM6.3Malicious configuration can lead to unauthorized file access in Apache Livy. This issue affects Apache Livy 0.7.0 and 0...
CVE-2025-57849MEDIUM6.4A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being...
CVE-2025-15515MEDIUM5.5The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific condit...
CVE-2025-14811MEDIUM5.9IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o...
CVE-2025-14504MEDIUM5.4IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2025-14483MEDIUM6.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2025-13702MEDIUM5.4IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site ...
CVE-2025-12454MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica ...
CVE-2025-12453MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica ...
CVE-2025-66955MEDIUM6.5Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated ...
CVE-2025-61154MEDIUM6.5Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cau...
CVE-2025-13913MEDIUM6.8A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which...
CVE-2025-15473MEDIUM4.3The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated us...
CVE-2025-15038MEDIUM6.9An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can ...
CVE-2025-15037MEDIUM6.8An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulne...
CVE-2025-12555MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 1...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now