2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20238MEDIUM6A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Def...
CVE-2025-20237MEDIUM6A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Def...
CVE-2025-20235MEDIUM6.1A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al...
CVE-2025-20225MEDIUM5.8A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Fi...
CVE-2025-20224MEDIUM5.8A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Applian...
CVE-2025-20220MEDIUM6A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat De...
CVE-2025-20219MEDIUM5.3A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive ...
CVE-2025-20218MEDIUM4.9A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could al...
CVE-2025-20135MEDIUM4.3A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and...
CVE-2025-54409MEDIUM5.5AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference v...
CVE-2025-54389MEDIUM5.5AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization...
CVE-2025-53631MEDIUM5.4flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitt...
CVE-2025-38745MEDIUM6.5Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log Fi...
CVE-2025-27847MEDIUM4.3In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.
CVE-2025-27846MEDIUM4.3In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges beca...
CVE-2025-26484MEDIUM4.9Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerabil...
CVE-2025-55675MEDIUM6.5Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization chec...
CVE-2025-55674MEDIUM6.5A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL fun...
CVE-2025-55673MEDIUM4.3When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query f...
CVE-2025-55672MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user...
CVE-2025-36581MEDIUM5.5Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and prior, contain(s) an Access of Memory Location After End of ...
CVE-2025-54706MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical ...
CVE-2025-54705MEDIUM4.3Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured...
CVE-2025-54704MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy El...
CVE-2025-54703MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Cros...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now