2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-50467MEDIUM6.5OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2025-50466MEDIUM6.5OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l...
CVE-2025-47872MEDIUM6.9The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and u...
CVE-2025-4576MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025...
CVE-2025-36023MEDIUM6.5IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authent...
CVE-2025-8749MEDIUM6.5Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR R...
CVE-2025-6572MEDIUM5.9The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does...
CVE-2025-54959MEDIUM5.3Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is explo...
CVE-2025-54958MEDIUM6.3Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is e...
CVE-2025-54940MEDIUM4.6An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerabilit...
CVE-2025-8707MEDIUM5.5A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unkn...
CVE-2025-54793MEDIUM6.1Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulner...
CVE-2025-54368MEDIUM6.8uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were hand...
CVE-2025-47808MEDIUM5.6In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while par...
CVE-2025-47807MEDIUM5.5In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer wh...
CVE-2025-47806MEDIUM5.6In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack ...
CVE-2025-47183MEDIUM6.6In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer whil...
CVE-2025-8697MEDIUM6.3A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function Stdi...
CVE-2025-7195MEDIUM6.4Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used...
CVE-2025-51533MEDIUM5.3An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access in...
CVE-2025-54397MEDIUM4.3Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Se...
CVE-2025-54396MEDIUM5.4Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated u...
CVE-2025-54395MEDIUM6.1Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configu...
CVE-2025-54394MEDIUM5.3Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credenti...
CVE-2025-54393MEDIUM5.4Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authent...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now