2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54291MEDIUM5.3Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remo...
CVE-2025-54290MEDIUM5.3Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to d...
CVE-2025-54288MEDIUM6.8Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attack...
CVE-2025-54287MEDIUM6.5Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance co...
CVE-2025-40646MEDIUM5.4Exposure of sensitive information in Viday. This vulnerability could allow an attacker to obtain sensitive information a...
CVE-2025-61583MEDIUM6.1TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability h...
CVE-2025-61587MEDIUM6.1Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter o...
CVE-2025-59337MEDIUM6.8Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be...
CVE-2025-57389MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 all...
CVE-2025-61189MEDIUM6.3Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFil...
CVE-2025-61188MEDIUM6.3Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers...
CVE-2025-59149MEDIUM6.2Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-57444MEDIUM6.1An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Man...
CVE-2025-59682MEDIUM6.5An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.e...
CVE-2025-58055MEDIUM4.3Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endp...
CVE-2025-58054MEDIUM5.4Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks throug...
CVE-2025-34182MEDIUM5.1In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the paramet...
CVE-2025-20370MEDIUM4.9In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.1...
CVE-2025-20369MEDIUM6.5In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3....
CVE-2025-20368MEDIUM5.4In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3....
CVE-2025-20367MEDIUM5.4In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2...
CVE-2025-20366MEDIUM6.5In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3....
CVE-2025-20361MEDIUM4.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...
CVE-2025-20357MEDIUM5.4A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote ...
CVE-2025-20356MEDIUM5.4A vulnerability in the web-based management interface of Cisco Cyber Vision Center could allow an authenticated, remote ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now