2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-55084MEDIUM5.3In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_...
CVE-2025-10849MEDIUM5.3The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2025-0275MEDIUM4.3HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset ...
CVE-2025-11814MEDIUM6.4The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to...
CVE-2025-0274MEDIUM4.3HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users ca...
CVE-2025-10700MEDIUM4.3The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2025-11683MEDIUM6.5YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential info...
CVE-2025-62375MEDIUM6.9go-witness and witness are Go modules for generating attestations. In go-witness versions 0.8.6 and earlier and witness ...
CVE-2025-43313MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, ...
CVE-2025-43282MEDIUM5.5A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPad...
CVE-2025-43280MEDIUM4.7The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an emai...
CVE-2025-11568MEDIUM4.4A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption for...
CVE-2025-62378MEDIUM6.1CommandKit is the discord.js meta-framework for building Discord bots. In versions 1.2.0-rc.1 through 1.2.0-rc.11, a log...
CVE-2025-58132MEDIUM6.5Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of informatio...
CVE-2025-54271MEDIUM5.6Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Conditio...
CVE-2025-20360MEDIUM5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,...
CVE-2025-20351MEDIUM6.1A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon...
CVE-2025-20329MEDIUM4.9A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software cou...
CVE-2025-61933MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker...
CVE-2025-59419MEDIUM5.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final...
CVE-2025-53860MEDIUM4.1A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIP...
CVE-2025-9548MEDIUM6.8A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a...
CVE-2025-56748MEDIUM6.4Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templat...
CVE-2025-55083MEDIUM5.3In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check result...
CVE-2025-10699MEDIUM6A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow inform...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now