2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-26400MEDIUM6.5SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could ...
CVE-2025-53649MEDIUM5.9"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V...
CVE-2025-53080MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) al...
CVE-2025-53079MEDIUM4.9Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sen...
CVE-2025-53077MEDIUM6.5An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without...
CVE-2025-4566MEDIUM6.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-4370MEDIUM5.3The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on proc...
CVE-2025-3075MEDIUM5.4The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2025-7811MEDIUM6.4The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2025-7810MEDIUM5.4The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'd...
CVE-2025-7809MEDIUM6.4The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2025-54768MEDIUM5.3An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ...
CVE-2025-54767MEDIUM6.5An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd...
CVE-2025-54766MEDIUM5.3An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ...
CVE-2025-54765MEDIUM5.3An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level ...
CVE-2025-54429MEDIUM6.9Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account addre...
CVE-2025-54427MEDIUM6.9Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_pric...
CVE-2025-54423MEDIUM6.1copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is abl...
CVE-2025-7676MEDIUM5.4DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute...
CVE-2025-54538MEDIUM5.5In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
CVE-2025-54537MEDIUM5.5In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
CVE-2025-54534MEDIUM4.8In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
CVE-2025-54533MEDIUM4.3In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
CVE-2025-54532MEDIUM4.3In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependenc...
CVE-2025-54527MEDIUM6.1In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now