2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-11848MEDIUM4.9A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version throu...
CVE-2025-11847MEDIUM4.9A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions thro...
CVE-2025-11846MEDIUM4.9A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions...
CVE-2025-11845MEDIUM4.9A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware ve...
CVE-2025-69253MEDIUM5.3free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of th...
CVE-2025-69251MEDIUM5.3free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co...
CVE-2025-69208MEDIUM5.3free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core...
CVE-2025-68930MEDIUM6.5Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijack...
CVE-2025-61147MEDIUM6.2strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::comp...
CVE-2025-61146MEDIUM4saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
CVE-2025-61145MEDIUM5libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
CVE-2025-61143MEDIUM5.5libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
CVE-2025-70044MEDIUM6.5An issue pertaining to CWE-295: Improper Certificate Validation was discovered in fofolee uTools-quickcommand 5.0.3.
CVE-2025-59873MEDIUM5.9An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits s...
CVE-2025-40986MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in PideTuCita. This vulnerability allows an attacker to execute JavaS...
CVE-2025-40701MEDIUM5.1Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute J...
CVE-2025-14339MEDIUM6.5The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo...
CVE-2025-65995MEDIUM6.5When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operat...
CVE-2025-62326MEDIUM4.8HCL Digital Experience is susceptible to stored cross-site scripting (XSS) in the administrative user interface which wo...
CVE-2025-15583MEDIUM5.4A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file uti...
CVE-2025-69388MEDIUM6.5Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access...
CVE-2025-69385MEDIUM6.5Missing Authorization vulnerability in AgniHD Cartify - WooCommerce Gutenberg WordPress Theme cartify allows Exploiting ...
CVE-2025-69325MEDIUM5.3Path Traversal: '.../...//' vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Path Trav...
CVE-2025-69011MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Cool Tag Cl...
CVE-2025-68895MEDIUM6.5Authentication Bypass Using an Alternate Path or Channel vulnerability in ahachat AhaChat Messenger Marketing ahachat-me...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now