2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6444MEDIUM5.9ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This vulnerability allows remote attac...
CVE-2025-5833MEDIUM6.8Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity Vulnerability. This vulnerability a...
CVE-2025-5832MEDIUM6.8Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity Vulnerability. This vulnera...
CVE-2025-5829MEDIUM6.8Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This...
CVE-2025-5828MEDIUM6.8Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-5826MEDIUM6.3Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerabili...
CVE-2025-5823MEDIUM6.5Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. Thi...
CVE-2025-49550MEDIUM4.3Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Author...
CVE-2025-6442MEDIUM5.9Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arb...
CVE-2025-52893MEDIUM4.5OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-52576MEDIUM5.3Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vul...
CVE-2025-52569MEDIUM6.6GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of i...
CVE-2025-50179MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a...
CVE-2025-50178MEDIUM6.6GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for ...
CVE-2025-44206MEDIUM4.6Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2...
CVE-2025-20264MEDIUM6.4A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2025-49135MEDIUM6.5CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 ha...
CVE-2025-48991MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a...
CVE-2025-48954MEDIUM6.1Discourse is an open-source discussion platform. Versions prior to 3.5.0.beta6 are vulnerable to cross-site scripting wh...
CVE-2025-25012MEDIUM5.4URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and ser...
CVE-2025-6603MEDIUM5.3A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as pro...
CVE-2025-6613MEDIUM5.4A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulne...
CVE-2025-41647MEDIUM5.5A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorre...
CVE-2025-43880MEDIUM5.3Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may caus...
CVE-2025-5585MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM E...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now