2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-69620MEDIUM5A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the in...
CVE-2025-36033MEDIUM5.4IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 th...
CVE-2025-33081MEDIUM5.5IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user...
CVE-2025-65081MEDIUM6.9An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This v...
CVE-2025-65080MEDIUM6.9A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulner...
CVE-2025-65079MEDIUM6.9A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices....
CVE-2025-64098MEDIUM5.9Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ...
CVE-2025-52633MEDIUM5.3HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensiti...
CVE-2025-52623MEDIUM6.5HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow au...
CVE-2025-71179MEDIUM6.1Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to t...
CVE-2025-70849MEDIUM6.1Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST ...
CVE-2025-70559MEDIUM6.5pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The libra...
CVE-2025-70311MEDIUM6.5JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 paramet...
CVE-2025-69848MEDIUM5.4NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scr...
CVE-2025-69431MEDIUM6.1The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB dri...
CVE-2025-69430MEDIUM6.1An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or...
CVE-2025-69429MEDIUM6.1The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploi...
CVE-2025-67189MEDIUM6.5A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The...
CVE-2025-65924MEDIUM4.1ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are inte...
CVE-2025-65923MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1...
CVE-2025-63372MEDIUM4.3Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the Z...
CVE-2025-58348MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58347MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58346MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58345MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now