2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-50740MEDIUM6.1AutoConnect 1.4.2, an Arduino library, is vulnerable to a cross site scripting (xss) vulnerability. The AutoConnect web ...
CVE-2025-46660MEDIUM5.3An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.
CVE-2025-8667MEDIUM6.3A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75b...
CVE-2025-8665MEDIUM6.3A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the f...
CVE-2025-8419MEDIUM5.3A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Inje...
CVE-2025-20332MEDIUM4.3A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modi...
CVE-2025-20331MEDIUM5.4A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot...
CVE-2025-20215MEDIUM5.4A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network...
CVE-2025-51531MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arb...
CVE-2025-48394MEDIUM4.7An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the...
CVE-2025-48393MEDIUM5.7The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potential...
CVE-2025-51308MEDIUM5.3In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a R...
CVE-2025-51306MEDIUM6.5In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the ap...
CVE-2025-50234MEDIUM6.5MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where ...
CVE-2025-50233MEDIUM6.5A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insuffic...
CVE-2025-2028MEDIUM5.3Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying coun...
CVE-2025-8616MEDIUM6.1A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the use...
CVE-2025-5197MEDIUM5.3A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifical...
CVE-2025-46391MEDIUM6.5CWE-284: Improper Access Control
CVE-2025-46389MEDIUM6.5CWE-620: Unverified Password Change
CVE-2025-46388MEDIUM4.3CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-8620MEDIUM5.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all ...
CVE-2025-7202MEDIUM5.1A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malic...
CVE-2025-27072MEDIUM5.5Information disclosure while processing a packet at EAVB BE side with invalid header length.
CVE-2025-21472MEDIUM5.5Information disclosure while capturing logs as eSE debug messages are logged.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now