2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-25026MEDIUM4.3IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authent...
CVE-2025-25025MEDIUM5.3IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error...
CVE-2025-2796MEDIUM5.3On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection confi...
CVE-2025-40911MEDIUM6.5Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address s...
CVE-2025-5283MEDIUM5.4Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap c...
CVE-2025-5281MEDIUM5.4Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially...
CVE-2025-5278MEDIUM4.4A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The...
CVE-2025-5198MEDIUM5.4A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a s...
CVE-2025-5067MEDIUM5.4Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform U...
CVE-2025-5066MEDIUM6.5Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker wh...
CVE-2025-5065MEDIUM6.5Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker t...
CVE-2025-5064MEDIUM5.4Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker t...
CVE-2025-46173MEDIUM6.1code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the fee...
CVE-2025-45475MEDIUM5.4maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
CVE-2025-22377MEDIUM6.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-27701MEDIUM5.5In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after ca...
CVE-2025-3704MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DBAR Productions V...
CVE-2025-5271MEDIUM6.5Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerab...
CVE-2025-5267MEDIUM5.4A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious...
CVE-2025-5266MEDIUM4.3Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leak...
CVE-2025-5265MEDIUM4.8Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user in...
CVE-2025-5264MEDIUM4.8Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into...
CVE-2025-5263MEDIUM4.3Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin lea...
CVE-2025-4412MEDIUM4.8On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it ...
CVE-2025-23393MEDIUM5.6A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in  spacewalk-java allows ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now