2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54478MEDIUM5.3Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which...
CVE-2025-54458MEDIUM5Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows a...
CVE-2025-53910MEDIUM4Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ...
CVE-2025-53514MEDIUM5.9Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the ...
CVE-2025-51824MEDIUM6.5libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.
CVE-2025-51823MEDIUM6.5libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parame...
CVE-2025-48731MEDIUM6.4Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows a...
CVE-2025-44001MEDIUM4Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers ...
CVE-2025-25229MEDIUM5.4Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privi...
CVE-2025-8866MEDIUM5.1YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An un...
CVE-2025-38499MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_...
CVE-2025-8865MEDIUM4.1The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when...
CVE-2025-8864MEDIUM6.8Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup lo...
CVE-2025-8852MEDIUM4.3A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/u...
CVE-2025-8851MEDIUM5.3A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffe...
CVE-2025-8847MEDIUM5.4A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the...
CVE-2025-8844MEDIUM5.5A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_te...
CVE-2025-8841MEDIUM6.1A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the func...
CVE-2025-8840MEDIUM5.4A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/delete...
CVE-2025-8661MEDIUM6.1A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data e...
CVE-2025-8835MEDIUM5.5A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of th...
CVE-2025-7965MEDIUM4.3The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, ...
CVE-2025-27562MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2025-27536MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.
CVE-2025-26690MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now