2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-9708MEDIUM6.8A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed c...
CVE-2025-43805MEDIUM5.3Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92...
CVE-2025-10566MEDIUM6.1A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unkno...
CVE-2025-49728MEDIUM4Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security ...
CVE-2025-47967MEDIUM4.7Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform...
CVE-2025-54237MEDIUM5.5Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to m...
CVE-2025-59336MEDIUM6.9Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of s...
CVE-2025-58174MEDIUM4.6LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM before 9.3 allows stor...
CVE-2025-58749MEDIUM5.3WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2...
CVE-2025-57145MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The...
CVE-2025-56293MEDIUM5.4code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Informat...
CVE-2025-56289MEDIUM5.4code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak ad...
CVE-2025-56280MEDIUM5.4code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit...
CVE-2025-36244MEDIUM5.5IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local use...
CVE-2025-8276MEDIUM4.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi...
CVE-2025-8057MEDIUM6.5Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Impro...
CVE-2025-56276MEDIUM5.4code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. ...
CVE-2025-39834MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_action_get_sh...
CVE-2025-39833MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitiali...
CVE-2025-39832MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix lockdep assertion on sync reset unloa...
CVE-2025-39831MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fbnic: Move phylink resume out of service_task and ...
CVE-2025-39830MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_pool_buddy_in...
CVE-2025-7355MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Beefull Energy Technologies Beefull App allows Exploit...
CVE-2025-55834MEDIUM6.1A Cross Site Scripting vulnerability in JeeWMS v.3.7 and before allows a remote attacker to obtain sensitive information...
CVE-2025-55117MEDIUM6.3A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now