2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54583MEDIUM6.5GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 ...
CVE-2025-54575MEDIUM5.3ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file con...
CVE-2025-51954MEDIUM6.1playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2025-51951MEDIUM6.1andisearch v0.5.249 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2025-50464MEDIUM6.5A buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability ar...
CVE-2025-36608MEDIUM6.5Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Refe...
CVE-2025-30103MEDIUM5.5Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories Accessible to External Partie...
CVE-2025-30480MEDIUM6.5Dell PowerProtect Data Manager, versions prior to 19.19, contain(s) an Improper Input Validation vulnerability in PowerP...
CVE-2025-30105MEDIUM5.5Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low p...
CVE-2025-26332MEDIUM5.5TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log ...
CVE-2025-45619MEDIUM6.5An issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction ...
CVE-2025-25692MEDIUM6.5A PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitr...
CVE-2025-25691MEDIUM6.5A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute ar...
CVE-2025-8353MEDIUM5.9UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 an...
CVE-2025-54656MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** Improper Output Neutralization for Logs vulnerability in Apache Struts. This issue affe...
CVE-2025-54573MEDIUM6.5CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0...
CVE-2025-53357MEDIUM5.4GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that...
CVE-2025-53112MEDIUM4.3GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2025-53111MEDIUM6.5GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks c...
CVE-2025-43018MEDIUM5.3Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a dev...
CVE-2025-54572MEDIUM6.9The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denia...
CVE-2025-54425MEDIUM5.3Umbraco is an ASP.NET CMS. In versions 13.0.0 through 13.9.2, 15.0.0 through 15.4.1 and 16.0.0 through 16.1.0, the conte...
CVE-2025-54410MEDIUM5.2Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Conta...
CVE-2025-54388MEDIUM4.6Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Conta...
CVE-2025-53008MEDIUM6.5GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now