2025 CVE Vulnerabilities

45,150 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-10746MEDIUM6.5The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and incl...
CVE-2025-61685MEDIUM6.5Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vuln...
CVE-2025-61681MEDIUM5.4KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its fi...
CVE-2025-61680MEDIUM6.6Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0....
CVE-2025-43825MEDIUM6.5A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 throug...
CVE-2025-10696MEDIUM5.4OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does no...
CVE-2025-10695MEDIUM5.3Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied d...
CVE-2025-59829MEDIUM6.5Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission de...
CVE-2025-53354MEDIUM6.1NiceGUI is a Python-based UI framework. Versions 2.24.2 and below are at risk for Cross-Site Scripting (XSS) when develo...
CVE-2025-54154MEDIUM6.8An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical a...
CVE-2025-53407MEDIUM6.5A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2025-53406MEDIUM6.5A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2025-52867MEDIUM6.5An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains...
CVE-2025-52866MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52862MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52860MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52859MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52858MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52857MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52855MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52854MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52853MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-52658MEDIUM4.8HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security...
CVE-2025-52654MEDIUM4.6HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output w...
CVE-2025-52433MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now