2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-47872MEDIUM6.9The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and u...
CVE-2025-4576MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025...
CVE-2025-36023MEDIUM6.5IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authent...
CVE-2025-8749MEDIUM6.5Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR R...
CVE-2025-6572MEDIUM5.9The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does...
CVE-2025-54959MEDIUM5.3Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is explo...
CVE-2025-54958MEDIUM6.3Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is e...
CVE-2025-54940MEDIUM4.6An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerabilit...
CVE-2025-8707MEDIUM5.5A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unkn...
CVE-2025-54793MEDIUM6.1Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulner...
CVE-2025-54368MEDIUM6.8uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were hand...
CVE-2025-47808MEDIUM5.6In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while par...
CVE-2025-47807MEDIUM5.5In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer wh...
CVE-2025-47806MEDIUM5.6In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack ...
CVE-2025-47183MEDIUM6.6In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer whil...
CVE-2025-8697MEDIUM6.3A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function Stdi...
CVE-2025-7195MEDIUM6.4Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used...
CVE-2025-51533MEDIUM5.3An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access in...
CVE-2025-54397MEDIUM4.3Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Se...
CVE-2025-54396MEDIUM5.4Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated u...
CVE-2025-54395MEDIUM6.1Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configu...
CVE-2025-54394MEDIUM5.3Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credenti...
CVE-2025-54393MEDIUM5.4Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authent...
CVE-2025-54392MEDIUM6.1Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d...
CVE-2025-7054MEDIUM6.5Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now