2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64070MEDIUM5.4Sourcecodester Student Grades Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the Add New Subject ...
CVE-2025-13828CRITICAL9SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even...
CVE-2025-13827HIGH8.8Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not res...
CVE-2025-65187MEDIUM6.1A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authentica...
CVE-2025-64460HIGH7.5An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django...
CVE-2025-63872MEDIUM6.1DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated ...
CVE-2025-59704MEDIUM4.6Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the ...
CVE-2025-59703CRITICAL9.1Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker...
CVE-2025-58113MEDIUM6.5An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.7.3.401...
CVE-2025-13877MEDIUM5.6A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the ...
CVE-2025-13372MEDIUM4.3An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to ...
CVE-2025-12630MEDIUM4.9The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability ch...
CVE-2025-59705MEDIUM6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker...
CVE-2025-59702HIGH7.2Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-59701MEDIUM4.1Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-59700LOW3.9Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-59699MEDIUM6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-59698MEDIUM6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate at...
CVE-2025-59697HIGH7.2Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-59696LOW3.2Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker...
CVE-2025-59695CRITICAL9.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to a...
CVE-2025-59694MEDIUM6.8The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow...
CVE-2025-59693CRITICAL9.8The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow...
CVE-2025-13876HIGH7.8A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is ...
CVE-2025-13875MEDIUM6.3A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now