2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58051MEDIUM6.5Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when impor...
CVE-2025-56700MEDIUM5.4Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allo...
CVE-2025-56699MEDIUM5.4SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows...
CVE-2025-53092MEDIUM6.5Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfigura...
CVE-2025-25298MEDIUM5.3Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum passwor...
CVE-2025-9559MEDIUM6.5Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user inter...
CVE-2025-62493MEDIUM6.5A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect...
CVE-2025-62492MEDIUM6.5A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation o...
CVE-2025-55035MEDIUM6.1Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a se...
CVE-2025-11842MEDIUM6.3A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function ...
CVE-2025-11840MEDIUM5.5A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. E...
CVE-2025-61540MEDIUM6.5SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
CVE-2025-61539MEDIUM6.1Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.
CVE-2025-41254MEDIUM4.3STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized me...
CVE-2025-36002MEDIUM5.5IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, ...
CVE-2025-53950MEDIUM6An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's O...
CVE-2025-46752MEDIUM4.4A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 al...
CVE-2025-11839MEDIUM5.5A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Perf...
CVE-2025-9955MEDIUM5.7An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission res...
CVE-2025-9804MEDIUM6.5An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in ...
CVE-2025-3930MEDIUM6.3Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, ...
CVE-2025-58426MEDIUM5.3desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious...
CVE-2025-58079MEDIUM5.3Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker...
CVE-2025-55072MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaS...
CVE-2025-54859MEDIUM4.8Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaS...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now