2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-62307MEDIUM5.4HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, ...
CVE-2025-53999MEDIUM6.5Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
CVE-2025-14602MEDIUM5.3The application generates uploaded file names using a weak and predictable method based on the request timestamp. This a...
CVE-2025-36398MEDIUM5.4IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authe...
CVE-2025-11729MEDIUM4.3The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized acc...
CVE-2025-9211MEDIUM6.7Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 al...
CVE-2025-10005MEDIUM4.3The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure ...
CVE-2025-71405MEDIUM5.1chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses t...
CVE-2025-10308MEDIUM4.3The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-62314MEDIUM5.6HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or s...
CVE-2025-52640MEDIUM4.7HCL AION is affected by a vulnerability where the shared storage used by product components is architected without suffi...
CVE-2025-59320MEDIUM4.6CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk s...
CVE-2025-41771MEDIUM4.3An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl...
CVE-2025-15687MEDIUM4.3A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF ...
CVE-2025-15686MEDIUM4.3A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the com...
CVE-2025-15685MEDIUM6.3A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the componen...
CVE-2025-15684MEDIUM5.3A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/com...
CVE-2025-48506MEDIUM4.6Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into t...
CVE-2025-35987MEDIUM4.3Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives...
CVE-2025-35973MEDIUM4.5Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow a...
CVE-2025-31938MEDIUM4.3Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(...
CVE-2025-31936MEDIUM5.7Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) ...
CVE-2025-31356MEDIUM5.7Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: H...
CVE-2025-0041MEDIUM4.6Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a...
CVE-2025-30240MEDIUM5.1The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now