2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48473MEDIUM4.3FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation fro...
CVE-2025-4081MEDIUM4.8Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and library load constraints al...
CVE-2025-5320MEDIUM6.3A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This affects the function is...
CVE-2025-46080MEDIUM5.3HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and cr...
CVE-2025-46078MEDIUM5.3HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server
CVE-2025-37999MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/erofs/fileio: call erofs_onlinefolio_split() aft...
CVE-2025-37998MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output...
CVE-2025-37997MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types ...
CVE-2025-37996MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in u...
CVE-2025-37995MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for modul...
CVE-2025-37994MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer acc...
CVE-2025-37993MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize ...
CVE-2025-33043MEDIUM6.1APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exp...
CVE-2025-48046MEDIUM5.3An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP GET request to the /co...
CVE-2025-48388MEDIUM6.5FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insuffi...
CVE-2025-5286MEDIUM6.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ pa...
CVE-2025-5122MEDIUM6.4The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all v...
CVE-2025-4670MEDIUM5.4The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored...
CVE-2025-5273MEDIUM6.9Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to Externa...
CVE-2025-4583MEDIUM5.4The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2025-27703MEDIUM6CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to ver...
CVE-2025-27702MEDIUM4.9CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers...
CVE-2025-5256MEDIUM5.4SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability...
CVE-2025-48747MEDIUM5Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incor...
CVE-2025-47748MEDIUM5.3Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now