2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-57354MEDIUM6.5A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user...
CVE-2025-57353MEDIUM5.3The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Du...
CVE-2025-57352MEDIUM5.3A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespa...
CVE-2025-48867MEDIUM4.8Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerabi...
CVE-2025-20338MEDIUM6.7A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative pri...
CVE-2025-20316MEDIUM5.3A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X...
CVE-2025-20314MEDIUM6.7A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an una...
CVE-2025-20313MEDIUM6.7Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileg...
CVE-2025-20293MEDIUM5.3A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for ...
CVE-2025-20240MEDIUM6.1A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attack...
CVE-2025-20149MEDIUM6.5A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker ...
CVE-2025-20365MEDIUM4.3A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an un...
CVE-2025-20364MEDIUM4.3A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow...
CVE-2025-20339MEDIUM5.8A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow a...
CVE-2025-27036MEDIUM6.1Information disclosure when Video engine escape input data is less than expected minimum size.
CVE-2025-27033MEDIUM6.1Information disclosure while running video usecase having rogue firmware.
CVE-2025-27030MEDIUM6.1information disclosure while invoking calibration data from user space to update firmware size.
CVE-2025-10360MEDIUM6.9In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant...
CVE-2025-8869MEDIUM5.9When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module...
CVE-2025-23338MEDIUM5.5NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write...
CVE-2025-23274MEDIUM4.5NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a mali...
CVE-2025-23273MEDIUM4.7NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a di...
CVE-2025-23272MEDIUM5.7NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially...
CVE-2025-9353MEDIUM6.4The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers...
CVE-2025-60020MEDIUM6.4nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in p...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now