2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-48012MEDIUM4.8Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Cre...
CVE-2025-48011MEDIUM4.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality ...
CVE-2025-48010MEDIUM4.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality ...
CVE-2025-45754MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inj...
CVE-2025-25539MEDIUM6.5Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via...
CVE-2025-20267MEDIUM4.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2025-20258MEDIUM5.4A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitr...
CVE-2025-20257MEDIUM6.5A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual...
CVE-2025-20255MEDIUM4.3A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manip...
CVE-2025-20250MEDIUM6.1A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a...
CVE-2025-20247MEDIUM6.1A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a...
CVE-2025-20246MEDIUM6.1A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) a...
CVE-2025-20114MEDIUM4.3A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform...
CVE-2025-20112MEDIUM5.1A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authentica...
CVE-2025-0372MEDIUM5.9Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwo...
CVE-2025-48206MEDIUM6.1The ns_backup extension through 13.0.0 for TYPO3 allows XSS.
CVE-2025-48204MEDIUM6.8The ns_backup extension through 13.0.0 for TYPO3 allows command injection.
CVE-2025-48203MEDIUM6.4The cs_seo extension through 9.2.0 for TYPO3 allows XSS.
CVE-2025-48202MEDIUM5.3The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-5029MEDIUM5.4A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classifie...
CVE-2025-44895MEDIUM6.5FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4B...
CVE-2025-44892MEDIUM6.5FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_p...
CVE-2025-48417MEDIUM6.5The certificate and private key used for providing transport layer security for connections to the web interface (TCP po...
CVE-2025-48415MEDIUM6.2A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The ...
CVE-2025-1418MEDIUM5.1A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which cont...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now