2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-51053MEDIUM6.1A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject...
CVE-2025-51052MEDIUM6.5A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem ...
CVE-2025-50740MEDIUM6.1AutoConnect 1.4.2, an Arduino library, is vulnerable to a cross site scripting (xss) vulnerability. The AutoConnect web ...
CVE-2025-46660MEDIUM5.3An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.
CVE-2025-8667MEDIUM6.3A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75b...
CVE-2025-8665MEDIUM6.3A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the f...
CVE-2025-8419MEDIUM5.3A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Inje...
CVE-2025-20332MEDIUM4.3A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modi...
CVE-2025-20331MEDIUM5.4A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot...
CVE-2025-20215MEDIUM5.4A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network...
CVE-2025-51531MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arb...
CVE-2025-48394MEDIUM4.7An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the...
CVE-2025-48393MEDIUM5.7The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potential...
CVE-2025-51308MEDIUM5.3In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a R...
CVE-2025-51306MEDIUM6.5In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the ap...
CVE-2025-50234MEDIUM6.5MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where ...
CVE-2025-50233MEDIUM6.5A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insuffic...
CVE-2025-2028MEDIUM5.3Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying coun...
CVE-2025-8616MEDIUM6.1A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the use...
CVE-2025-5197MEDIUM5.3A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifical...
CVE-2025-46391MEDIUM6.5CWE-284: Improper Access Control
CVE-2025-46389MEDIUM6.5CWE-620: Unverified Password Change
CVE-2025-46388MEDIUM4.3CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-8620MEDIUM5.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all ...
CVE-2025-7202MEDIUM5.1A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now