2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7056MEDIUM6.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-6210MEDIUM6.2A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, al...
CVE-2025-5472MEDIUM6.5The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive...
CVE-2025-4779MEDIUM6.1lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attack...
CVE-2025-3705MEDIUM6.8A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of sp...
CVE-2025-3467MEDIUM5.4An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vu...
CVE-2025-3264MEDIUM5.3A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp...
CVE-2025-3263MEDIUM5.3A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp...
CVE-2025-3044MEDIUM5.3A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows ...
CVE-2025-7113MEDIUM5.4A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown fu...
CVE-2025-7112MEDIUM5.4A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown pr...
CVE-2025-7111MEDIUM5.4A vulnerability has been found in Portabilis i-Educar 2.9.0 and classified as problematic. This vulnerability affects un...
CVE-2025-24508MEDIUM6.4Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage
CVE-2025-7110MEDIUM5.4A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown pa...
CVE-2025-7109MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issu...
CVE-2025-7108MEDIUM5.4A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6.7. Affected by this vul...
CVE-2025-53186MEDIUM6.2Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Im...
CVE-2025-53185MEDIUM5.5Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access re...
CVE-2025-53178MEDIUM4.8Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may...
CVE-2025-53173MEDIUM4.3Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerabil...
CVE-2025-53170MEDIUM5.5Null pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vuln...
CVE-2025-53168MEDIUM5.7Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful e...
CVE-2025-7099MEDIUM5.9A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability...
CVE-2025-7095MEDIUM6.1A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an u...
CVE-2025-38235MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: fix "appletb_backlight" backlight...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now