2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-59544MEDIUM4.3Chamilo is a learning management system. Prior to version 1.11.34, the functionality for the user to update the category...
CVE-2025-59540MEDIUM5.4Chamilo is a learning management system. Prior to version 1.11.34, a stored XSS vulnerability exists in Chamilo LMS that...
CVE-2025-30413MEDIUM4.4Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber...
CVE-2025-11790MEDIUM4.4Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber...
CVE-2025-7375MEDIUM6.5A denial-of-service (DoS) vulnerability was identified in Omada EAP610 v3. An attacker with adjacent network access can...
CVE-2025-64166MEDIUM5.4Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability w...
CVE-2025-11143MEDIUM6.5The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Different...
CVE-2025-66319MEDIUM5.5Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerabilit...
CVE-2025-69343MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Thea...
CVE-2025-68515MEDIUM5.8Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allow...
CVE-2025-41257MEDIUM4.8Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting t...
CVE-2025-62879MEDIUM4.9A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both acce...
CVE-2025-59787MEDIUM6.52N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving ...
CVE-2025-12801MEDIUM6.5A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3...
CVE-2025-70342MEDIUM6.6erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.jso...
CVE-2025-40896MEDIUM4.8The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could per...
CVE-2025-40895MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on...
CVE-2025-40894MEDIUM5.4A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper valida...
CVE-2025-14456MEDIUM5.9IBM MQ Appliance 9.4 CD through 9.4.4.0 to 9.4.4.1
CVE-2025-13734MEDIUM5.4IBM Engineering Requirements Management DOORS Next 7.1, and 7.2 could allow an authenticated user to view and edit data ...
CVE-2025-13490MEDIUM5.9IBM App Connect Operator versions CD 11.3.0 through 11.6.0 and 12.1.0 through 12.20.0, LTS versions 12.0.0 through 12.0....
CVE-2025-15599MEDIUM6.1DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers...
CVE-2025-62816MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4...
CVE-2025-62815MEDIUM5.5An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference ...
CVE-2025-59060MEDIUM5.3Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now