2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66515LOW2.7The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenti...
CVE-2025-66514MEDIUM5.4Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injecti...
CVE-2025-66513MEDIUM5.3Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the inf...
CVE-2025-34266MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34265MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34264MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34263MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34262MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34261MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34260MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34259MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34258MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34257MEDIUM5.4Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /r...
CVE-2025-34256CRITICAL9.8Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product u...
CVE-2025-66552MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 3...
CVE-2025-66550MEDIUM5.7Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar ...
CVE-2025-66547MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-...
CVE-2025-66546LOW3.3Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly ...
CVE-2025-66512MEDIUM6.1Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and ...
CVE-2025-66511MEDIUM6.5Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for me...
CVE-2025-66510MEDIUM4.9Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud E...
CVE-2025-66471HIGH7.5urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API...
CVE-2025-65879HIGH8.1Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods ...
CVE-2025-65878HIGH7.5The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImage...
CVE-2025-65036HIGH8.3XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.2...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now