2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-53626MEDIUM6.1pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 ...
CVE-2025-53549MEDIUM5.2The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection v...
CVE-2025-52473MEDIUM5.5liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Mult...
CVE-2025-28245MEDIUM6.1Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web ...
CVE-2025-49464MEDIUM6.5Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service ...
CVE-2025-49463MEDIUM6.5Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated u...
CVE-2025-47813MEDIUM4.3loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a ...
CVE-2025-47811MEDIUM6.6In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or S...
CVE-2025-6395MEDIUM6.5A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().
CVE-2025-53364MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3....
CVE-2025-46789MEDIUM6.5Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service ...
CVE-2025-7408MEDIUM5.4A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerabi...
CVE-2025-36090MEDIUM5.3IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the applicati...
CVE-2025-6211MEDIUM6.5A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the...
CVE-2025-5022MEDIUM6.5Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV...
CVE-2025-3396MEDIUM4.3An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 ...
CVE-2025-38347MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on ino and xnid syzbo...
CVE-2025-38345MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ACPICA: fix acpi operand cache leak in dswstate.c ...
CVE-2025-38344MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ACPICA: fix acpi parse and parseext cache leaks AC...
CVE-2025-38343MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: drop fragments with multicast o...
CVE-2025-38339MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: powerpc/bpf: fix JIT code size calculation of bpf t...
CVE-2025-38337MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: jbd2: fix data-race and null-ptr-deref in jbd2_jour...
CVE-2025-38336MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ata: pata_via: Force PIO for ATAPI devices on VT641...
CVE-2025-38335MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Input: gpio-keys - fix a sleep while atomic with PR...
CVE-2025-38334MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Prevent attempts to reclaim poisoned pages...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now