2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48486MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) ...
CVE-2025-48485MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to...
CVE-2025-41406MEDIUM6.1Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected de...
CVE-2025-5259MEDIUM6.4The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in...
CVE-2025-4659MEDIUM5.3The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is v...
CVE-2025-4429MEDIUM6.1The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputt...
CVE-2025-48490MEDIUM6.6Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where mu...
CVE-2025-48484MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to...
CVE-2025-48483MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to...
CVE-2025-48482MEDIUM4.3FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulne...
CVE-2025-48478MEDIUM4.9FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation du...
CVE-2025-48381MEDIUM4.3Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In version...
CVE-2025-48068MEDIUM4.3Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 ...
CVE-2025-44612MEDIUM5.9Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control inform...
CVE-2025-31264MEDIUM4.6An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS S...
CVE-2025-31261MEDIUM5.5A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS...
CVE-2025-31231MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be...
CVE-2025-31199MEDIUM5.5A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequo...
CVE-2025-31198MEDIUM5.5This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 1...
CVE-2025-47933MEDIUM5.4Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.13.8, 2.14.13, and 3.0.4, ...
CVE-2025-3050MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could ...
CVE-2025-5324MEDIUM4.8A vulnerability, which was classified as problematic, was found in TechPowerUp GPU-Z 2.23.0. Affected is the function su...
CVE-2025-32752MEDIUM4.6Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacke...
CVE-2025-5323MEDIUM6.3A vulnerability, which was classified as problematic, has been found in fossasia open-event-server 1.19.1. This issue af...
CVE-2025-29632MEDIUM5.4Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now