2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62383MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62365MEDIUM6.1LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in...
CVE-2025-62362MEDIUM6.9gpp-burgerportaal is a Dutch government citizen portal application. In versions before 2.0.3, 3.0.2, and 4.0.1, the name...
CVE-2025-62361MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open ...
CVE-2025-62359MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, a Reflec...
CVE-2025-62358MEDIUM6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, the log ...
CVE-2025-62251MEDIUM6.5Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA...
CVE-2025-62178MEDIUM5.4WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a Reflec...
CVE-2025-11623MEDIUM6.5SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar...
CVE-2025-62364MEDIUM6.2text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Loc...
CVE-2025-62252MEDIUM4.3Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported v...
CVE-2025-62246MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsuppor...
CVE-2025-62176MEDIUM4.3Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27...
CVE-2025-62175MEDIUM4.3Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27...
CVE-2025-62242MEDIUM4.3Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111...
CVE-2025-62241MEDIUM4.3Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5...
CVE-2025-58084MEDIUM6.5Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing ...
CVE-2025-62243MEDIUM5.4Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Lif...
CVE-2025-61775MEDIUM6.9Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unex...
CVE-2025-62244MEDIUM4.3Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Lif...
CVE-2025-39965MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id....
CVE-2025-9337MEDIUM6.8A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a speciall...
CVE-2025-9336MEDIUM6.8A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipu...
CVE-2025-11184MEDIUM6.9Cross-site scripting vulnerability in QGIS QWC2 Registration GUI <=v2025.03.31 allows an authorized attacker to plant ar...
CVE-2025-11183MEDIUM6.9Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 <2025.08.14 allows an authorized attacker to plant ar...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now