2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20017MEDIUM6.7Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated u...
CVE-2025-8452MEDIUM4.3By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-fu...
CVE-2025-55011MEDIUM5.3Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskF...
CVE-2025-54800MEDIUM6.1Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can intro...
CVE-2025-3089MEDIUM5.3ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This v...
CVE-2025-5468MEDIUM5.5Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure bef...
CVE-2025-5466MEDIUM4.9XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before ...
CVE-2025-22834MEDIUM5.3AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Success...
CVE-2025-22830MEDIUM6.7APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A successful ex...
CVE-2025-43735MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024...
CVE-2025-40766MEDIUM6.8A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected a...
CVE-2025-40753MEDIUM6.8A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWE...
CVE-2025-40752MEDIUM6.8A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWE...
CVE-2025-40584MEDIUM6.8A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), S...
CVE-2025-33023MEDIUM5.1A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGE...
CVE-2025-30034MEDIUM5.5A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected devices do not prop...
CVE-2025-43736MEDIUM4.3A Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP...
CVE-2025-8885MEDIUM6.3Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on...
CVE-2025-26398MEDIUM6.4SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnera...
CVE-2025-8874MEDIUM6.4The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ...
CVE-2025-8767MEDIUM4.8The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16...
CVE-2025-8482MEDIUM4.3The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This ...
CVE-2025-47444MEDIUM5.3Missing Authorization vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Exploiting Incorrectly ...
CVE-2025-8081MEDIUM4.9The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via...
CVE-2025-3892MEDIUM6.7ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerabil...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now