2025 CVE Vulnerabilities

45,173 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-23269MEDIUM4.7NVIDIA Jetson Linux contains a vulnerability in the kernel where an attacker may cause an exposure of sensitive informat...
CVE-2025-6230MEDIUM5.3A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLit...
CVE-2025-2818MEDIUM5.1A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Co...
CVE-2025-1729MEDIUM6.7A DLL hijacking vulnerability was reported in TrackPoint Quick Menu software that, under certain conditions, could allow...
CVE-2025-54070MEDIUM6.9OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 5.2.0 and prior to versio...
CVE-2025-46102MEDIUM5.4Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Referenc...
CVE-2025-53638MEDIUM6.9Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, w...
CVE-2025-51497MEDIUM5.5An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Saf...
CVE-2025-54066MEDIUM4.7DiracX-Web is a web application that provides an interface to interact with the DiracX services. Prior to version 0.1.0-...
CVE-2025-54064MEDIUM6.9Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da...
CVE-2025-47189MEDIUM6.1Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error d...
CVE-2025-53941MEDIUM6.1Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to ...
CVE-2025-53927MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed be...
CVE-2025-40924MEDIUM6.5Catalyst::Plugin::Session before version 0.44 for Perl generates session ids insecurely. The session id is generated fr...
CVE-2025-5346MEDIUM5.1Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast recei...
CVE-2025-5345MEDIUM6.3Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "...
CVE-2025-3415MEDIUM4.3Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not p...
CVE-2025-4302MEDIUM5.3The Stop User Enumeration WordPress plugin before version 1.7.3 blocks REST API /wp-json/wp/v2/users/ requests for non-a...
CVE-2025-7729MEDIUM5.4A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unk...
CVE-2025-7728MEDIUM5.4A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of ...
CVE-2025-6983MEDIUM5.1A Clickjacking vulnerability in TP-Link Archer C1200 web management page allows an attacker to trick users into perfor...
CVE-2025-6982MEDIUM6.9Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 ...
CVE-2025-20288MEDIUM5.3A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticate...
CVE-2025-20285MEDIUM4.1A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote...
CVE-2025-20272MEDIUM4.3A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (E...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now