2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48019MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-70092MEDIUM5.5A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute...
CVE-2025-70845MEDIUM6.1lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) exists in the /setting/ page where the "intro" field is...
CVE-2025-14282MEDIUM5.4A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the...
CVE-2025-69752MEDIUM4.3An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view...
CVE-2025-56647MEDIUM6.5npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server d...
CVE-2025-13004MEDIUM6.3Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce P...
CVE-2025-13002MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Sof...
CVE-2025-15575MEDIUM5.3The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows at...
CVE-2025-15574MEDIUM6.5When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character stri...
CVE-2025-41117MEDIUM6.1Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the b...
CVE-2025-64074MEDIUM5.3A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows ...
CVE-2025-46310MEDIUM6This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14...
CVE-2025-46305MEDIUM5.7The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i...
CVE-2025-46304MEDIUM5.7The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i...
CVE-2025-46303MEDIUM5.7The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i...
CVE-2025-46302MEDIUM5.7The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i...
CVE-2025-46301MEDIUM5.7The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i...
CVE-2025-46300MEDIUM5.7The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and i...
CVE-2025-43537MEDIUM5.5A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 2...
CVE-2025-43417MEDIUM5.5A path handling issue was addressed with improved logic. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. A...
CVE-2025-43403MEDIUM5.5An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS ...
CVE-2025-68663MEDIUM5.3Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's...
CVE-2025-70297MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1...
CVE-2025-70296MEDIUM5.4A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticate...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now