2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-52650MEDIUM6.1Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
CVE-2025-41089MEDIUM4.8Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user in...
CVE-2025-41088MEDIUM5.1Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. T...
CVE-2025-37727MEDIUM5.7Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preco...
CVE-2025-25018MEDIUM5.4Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
CVE-2025-25017MEDIUM6.1Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
CVE-2025-40640MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du...
CVE-2025-62292MEDIUM4.3In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/...
CVE-2025-21070MEDIUM5.5Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-o...
CVE-2025-21065MEDIUM6.6Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands o...
CVE-2025-21064MEDIUM6.5Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.
CVE-2025-21063MEDIUM4.6Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16...
CVE-2025-21061MEDIUM5.5Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access se...
CVE-2025-21060MEDIUM5.5Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access ba...
CVE-2025-21059MEDIUM5.5Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung He...
CVE-2025-21054MEDIUM5.5Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local at...
CVE-2025-21050MEDIUM5.5Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across mult...
CVE-2025-21049MEDIUM5.5Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive inform...
CVE-2025-21047MEDIUM6.8Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged API...
CVE-2025-21045MEDIUM5.5Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to acce...
CVE-2025-21044MEDIUM4.4Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write o...
CVE-2025-10124MEDIUM4.5The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode...
CVE-2025-11570MEDIUM4.6Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XS...
CVE-2025-11450MEDIUM5.3ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor...
CVE-2025-11449MEDIUM5.3ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now