2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-61797MEDIUM5.4Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha...
CVE-2025-61796MEDIUM5.4Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha...
CVE-2025-54272MEDIUM5.4Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha...
CVE-2025-54196MEDIUM4.3Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerabil...
CVE-2025-54267MEDIUM6.5Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an...
CVE-2025-54266MEDIUM4.8Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a ...
CVE-2025-54265MEDIUM5.9Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an...
CVE-2025-62374MEDIUM6.4Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, inje...
CVE-2025-60540MEDIUM6.5karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF).
CVE-2025-60374MEDIUM6.1Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScrip...
CVE-2025-59429MEDIUM5.4FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior t...
CVE-2025-33177MEDIUM5.5NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could all...
CVE-2025-54275MEDIUM5.5Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could lead to...
CVE-2025-8459MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-60537MEDIUM6.5Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows a...
CVE-2025-57563MEDIUM6.5A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to rea...
CVE-2025-8430MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In...
CVE-2025-59497MEDIUM4.7Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny ...
CVE-2025-59294MEDIUM4.6Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to di...
CVE-2025-59288MEDIUM5.3Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofi...
CVE-2025-59284MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp...
CVE-2025-59260MEDIUM5.5Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an author...
CVE-2025-59259MEDIUM6.5Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d...
CVE-2025-59258MEDIUM6.2Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker...
CVE-2025-59257MEDIUM6.5Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now