2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64098MEDIUM5.9Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ...
CVE-2025-52633MEDIUM5.3HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensiti...
CVE-2025-52623MEDIUM6.5HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow au...
CVE-2025-71179MEDIUM6.1Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to t...
CVE-2025-70849MEDIUM6.1Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST ...
CVE-2025-70559MEDIUM6.5pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The libra...
CVE-2025-70311MEDIUM6.5JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 paramet...
CVE-2025-69848MEDIUM5.4NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scr...
CVE-2025-69431MEDIUM6.1The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB dri...
CVE-2025-69430MEDIUM6.1An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or...
CVE-2025-69429MEDIUM6.1The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploi...
CVE-2025-67189MEDIUM6.5A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The...
CVE-2025-65924MEDIUM4.1ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are inte...
CVE-2025-65923MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1...
CVE-2025-63372MEDIUM4.3Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the Z...
CVE-2025-58348MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58347MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58346MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58345MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58344MEDIUM6.2An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58343MEDIUM5.5An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58342MEDIUM6.2An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58341MEDIUM6.2An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-58340MEDIUM6.2An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 12...
CVE-2025-52629MEDIUM6.1HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now