2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22244MEDIUM6.9VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input vali...
CVE-2025-2336MEDIUM4.8Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'n...
CVE-2025-20279MEDIUM4.8A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker...
CVE-2025-20278MEDIUM6.7A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacke...
CVE-2025-20277MEDIUM6.7A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker ...
CVE-2025-20273MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise could a...
CVE-2025-20259MEDIUM5.3Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authentic...
CVE-2025-20129MEDIUM5.4A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMin...
CVE-2025-29094MEDIUM6.1Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbi...
CVE-2025-23106MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo...
CVE-2025-23101MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privi...
CVE-2025-23096MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile pro...
CVE-2025-23095MEDIUM6.5An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile pro...
CVE-2025-48962MEDIUM4.3Sensitive information disclosure due to SSRF. The following products are affected: Acronis Cyber Protect 16 (Windows, Li...
CVE-2025-48960MEDIUM5.9Weak server key used for TLS encryption. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Wi...
CVE-2025-48959MEDIUM6.7Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect ...
CVE-2025-5601MEDIUM6.5Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or...
CVE-2025-5584MEDIUM5.4A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been classified as problematic. Affected ...
CVE-2025-27444MEDIUM4.8A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from th...
CVE-2025-4580MEDIUM4.3The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which cou...
CVE-2025-48710MEDIUM4.1kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefin...
CVE-2025-5539MEDIUM6.4The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2025-20996MEDIUM5Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers...
CVE-2025-20993MEDIUM6.8Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write o...
CVE-2025-20991MEDIUM5.1Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now