2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48695MEDIUM6.4An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to...
CVE-2025-4594MEDIUM5.4The Tournamatch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trn-ladder-registrat...
CVE-2025-48701MEDIUM5.4openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.
CVE-2025-2394MEDIUM4.7Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alib...
CVE-2025-4692MEDIUM6.8Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation b...
CVE-2025-4338MEDIUM6.9Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the netwo...
CVE-2025-4975MEDIUM4.8When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notific...
CVE-2025-48374MEDIUM5.5zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to v...
CVE-2025-48369MEDIUM5.4Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20...
CVE-2025-48368MEDIUM5.4Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20...
CVE-2025-48366MEDIUM5.4Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.119 and 25.0.20...
CVE-2025-48066MEDIUM5.5wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an ...
CVE-2025-30173MEDIUM6.7File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue aff...
CVE-2025-30170MEDIUM5.9Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system inf...
CVE-2025-30169MEDIUM6.7File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become...
CVE-2025-48061MEDIUM5.6wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in...
CVE-2025-47779MEDIUM6.5Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste...
CVE-2025-46716MEDIUM5.5Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve...
CVE-2025-33138MEDIUM6.1IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2025-4366MEDIUM6.1A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP r...
CVE-2025-2506MEDIUM5.3When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user w...
CVE-2025-23183MEDIUM6.1CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CVE-2025-23182MEDIUM4.3CWE-203: Observable Discrepancy
CVE-2025-32915MEDIUM5.5Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2....
CVE-2025-32815MEDIUM6.5An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now