2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-24471MEDIUM6.5An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below m...
CVE-2025-24069MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-24068MEDIUM5.5Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-24065MEDIUM5.5Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-22251MEDIUM5.3An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 t...
CVE-2025-49143MEDIUM5.9Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by ...
CVE-2025-48937MEDIUM4.9matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 an...
CVE-2025-48879MEDIUM6.5OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to sen...
CVE-2025-48067MEDIUM4.6OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11....
CVE-2025-44043MEDIUM5.4Keyoti SearchUnit prior to 9.0.0. is vulnerable to Server-Side Request Forgery (SSRF) in /Keyoti_SearchEngine_Web_Common...
CVE-2025-40569MEDIUM5.9A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532...
CVE-2025-40568MEDIUM5.3A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK532...
CVE-2025-27207MEDIUM6.5Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access ...
CVE-2025-27206MEDIUM5.3Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access ...
CVE-2025-27505MEDIUM5.3GeoServer is an open source server that allows users to share and edit geospatial data. It is possible to bypass the def...
CVE-2025-26395MEDIUM4.3SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitiz...
CVE-2025-26394MEDIUM4.8SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sani...
CVE-2025-49510MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Min Max Step Quantity Limits Manager for WooCommerce produc...
CVE-2025-49509MEDIUM5.3Missing Authorization vulnerability in Roland Beaussant Audio Editor & Recorder audio-editor-recorder allows Exploiting ...
CVE-2025-4774MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdow...
CVE-2025-4577MEDIUM5.4The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cros...
CVE-2025-43699MEDIUM5.3Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of requ...
CVE-2025-2918MEDIUM5.4The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mult...
CVE-2025-41657MEDIUM4.3Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerpri...
CVE-2025-5742MEDIUM5.4CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now