2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-36002MEDIUM5.5IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, ...
CVE-2025-53950MEDIUM6An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's O...
CVE-2025-46752MEDIUM4.4A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 al...
CVE-2025-11839MEDIUM5.5A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Perf...
CVE-2025-9955MEDIUM5.7An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission res...
CVE-2025-9804MEDIUM6.5An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in ...
CVE-2025-3930MEDIUM6.3Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, ...
CVE-2025-58426MEDIUM5.3desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious...
CVE-2025-58079MEDIUM5.3Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker...
CVE-2025-55072MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaS...
CVE-2025-54859MEDIUM4.8Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaS...
CVE-2025-54760MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaS...
CVE-2025-52583MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a...
CVE-2025-24833MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary...
CVE-2025-58115MEDIUM5.3ChatLuck contains a cross-site scripting vulnerability in Guest User Sign-up. If exploited, an arbitrary script may be e...
CVE-2025-54461MEDIUM6.9ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited...
CVE-2025-53858MEDIUM5.4ChatLuck contains a cross-site scripting vulnerability in Chat Rooms. If exploited, an arbitrary script may be executed ...
CVE-2025-41410MEDIUM5.4Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Sl...
CVE-2025-10545MEDIUM4.3Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding c...
CVE-2025-0277MEDIUM6.1HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP)...
CVE-2025-0276MEDIUM6.1HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Conte...
CVE-2025-55091MEDIUM6.5In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...
CVE-2025-41443MEDIUM4.3Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessin...
CVE-2025-41021MEDIUM5.4Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validati...
CVE-2025-55090MEDIUM6.5In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bou...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now