2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-32803MEDIUM4In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, ...
CVE-2025-31501MEDIUM6.1Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
CVE-2025-31500MEDIUM6.1Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
CVE-2025-30087MEDIUM6.1Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted paramete...
CVE-2025-1461MEDIUM5.6Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsa...
CVE-2025-5257MEDIUM6.5SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by u...
CVE-2025-48931MEDIUM5.5The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibiliti...
CVE-2025-48930MEDIUM5.3The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content ma...
CVE-2025-48928MEDIUM4The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent...
CVE-2025-48927MEDIUM5.3The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heap...
CVE-2025-48746MEDIUM6.5Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authe...
CVE-2025-36572MEDIUM6.5Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image f...
CVE-2025-32802MEDIUM6.1Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. M...
CVE-2025-40651MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute ...
CVE-2025-4493MEDIUM6.5Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT req...
CVE-2025-5297MEDIUM6.6A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issu...
CVE-2025-40673MEDIUM5.3A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoi...
CVE-2025-4963MEDIUM6.4The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u...
CVE-2025-5082MEDIUM6.1The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ paramete...
CVE-2025-47294MEDIUM5.3A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may all...
CVE-2025-27526MEDIUM6.5Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through...
CVE-2025-27522MEDIUM6.5Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through...
CVE-2025-5025MEDIUM4.8libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is n...
CVE-2025-4947MEDIUM6.5libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an I...
CVE-2025-25029MEDIUM6.5IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now