2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-3473MEDIUM6.7IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inhe...
CVE-2025-0163MEDIUM5.3IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames...
CVE-2025-4605MEDIUM6.6A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnera...
CVE-2025-35941MEDIUM5.5A password is exposed locally.
CVE-2025-5144MEDIUM5.4The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ paramete...
CVE-2025-5986MEDIUM6.5A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's de...
CVE-2025-4573MEDIUM4.1Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LD...
CVE-2025-4128MEDIUM4.3Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowi...
CVE-2025-26412MEDIUM6.8The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with ...
CVE-2025-4798MEDIUM4.9The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1...
CVE-2025-4666MEDIUM6.4The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all versi...
CVE-2025-30675MEDIUM4.7In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or ...
CVE-2025-1055MEDIUM5.6A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege use...
CVE-2025-5984MEDIUM5.4A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affe...
CVE-2025-47117MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47116MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47115MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47114MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47113MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47094MEDIUM6.1Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-47093MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47092MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47091MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47090MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-47089MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now