2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20149MEDIUM6.5A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker ...
CVE-2025-20365MEDIUM4.3A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an un...
CVE-2025-20364MEDIUM4.3A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow...
CVE-2025-20339MEDIUM5.8A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow a...
CVE-2025-27036MEDIUM6.1Information disclosure when Video engine escape input data is less than expected minimum size.
CVE-2025-27033MEDIUM6.1Information disclosure while running video usecase having rogue firmware.
CVE-2025-27030MEDIUM6.1information disclosure while invoking calibration data from user space to update firmware size.
CVE-2025-10360MEDIUM6.9In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant...
CVE-2025-8869MEDIUM5.9When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module...
CVE-2025-23338MEDIUM5.5NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write...
CVE-2025-23274MEDIUM4.5NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a mali...
CVE-2025-23273MEDIUM4.7NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a di...
CVE-2025-23272MEDIUM5.7NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially...
CVE-2025-9353MEDIUM6.4The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers...
CVE-2025-60020MEDIUM6.4nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in p...
CVE-2025-39890MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_rea...
CVE-2025-39889MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on inco...
CVE-2025-58457MEDIUM4.3Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insu...
CVE-2025-9031MEDIUM4.3Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Doma...
CVE-2025-41716MEDIUM5.3The web application allows an unauthenticated remote attacker to learn information about existing user accounts with the...
CVE-2025-48459MEDIUM5.3Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0...
CVE-2025-43819MEDIUM6.5A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024....
CVE-2025-43779MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024...
CVE-2025-58069MEDIUM6.9The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerabili...
CVE-2025-54855MEDIUM4.2Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now