2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54789MEDIUM6.1Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functi...
CVE-2025-54792MEDIUM6.8LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without nee...
CVE-2025-8474MEDIUM6.8Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically pr...
CVE-2025-8473MEDIUM6.6Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attack...
CVE-2025-6037MEDIUM6.8Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when con...
CVE-2025-6015MEDIUM5.7Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in...
CVE-2025-6014MEDIUM6.5Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within ...
CVE-2025-6004MEDIUM5.3Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication metho...
CVE-2025-54590MEDIUM6.9webfinger.js is a TypeScript-based WebFinger client that runs in both browsers and Node.js environments. In versions 2.8...
CVE-2025-50869MEDIUM6.1A stored Cross-Site Scripting (XSS) vulnerability exists in the qureydetails.php page of Institute-of-Current-Students 1...
CVE-2025-50868MEDIUM6.5A SQL Injection vulnerability exists in the takeassessment2.php file of CloudClassroom-PHP-Project 1.0. The Q4 POST para...
CVE-2025-49832MEDIUM6.5Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, betwe...
CVE-2025-33118MEDIUM5.4IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows...
CVE-2025-51502MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allow...
CVE-2025-51501MEDIUM6.1Reflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS...
CVE-2025-48074MEDIUM5.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2025-45778MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute...
CVE-2025-46018MEDIUM5.4CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorizat...
CVE-2025-41376MEDIUM5.3CRLF Injection vulnerability in Limesurvey v2.65.1+170522.  This vulnerability could allow a remote attacker to inject a...
CVE-2025-6228MEDIUM6.4The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Tabl...
CVE-2025-4684MEDIUM6.4The BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Count...
CVE-2025-6398MEDIUM6.7A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be t...
CVE-2025-7646MEDIUM6.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2025-5921MEDIUM5.8The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2025-31716MEDIUM5.1In bootloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now