2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-54148MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-54147MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-54146MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-53598MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-48722MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-47209MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-47205MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2025-30266MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac...
CVE-2025-14592MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 1...
CVE-2025-14560MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 1...
CVE-2025-12575MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8...
CVE-2025-12073MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 18.6.6, 18.7 before 18.7.4, and 1...
CVE-2025-13650MEDIUM6.1An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not neces...
CVE-2025-13649MEDIUM6.1An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not nec...
CVE-2025-13648MEDIUM6.1An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is require...
CVE-2025-10912MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikY...
CVE-2025-15400MEDIUM6.5The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that r...
CVE-2025-15524MEDIUM4.3The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2025-13431MEDIUM6.5The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all ve...
CVE-2025-12699MEDIUM6.7The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PC...
CVE-2025-54514MEDIUM4.8Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could po...
CVE-2025-52536MEDIUM6.7Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware pot...
CVE-2025-52534MEDIUM5.3Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting...
CVE-2025-48517MEDIUM4.6Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to ...
CVE-2025-48515MEDIUM5.4Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPI...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now