2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-4478MEDIUM6.5A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a se...
CVE-2025-47794MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Ne...
CVE-2025-47793MEDIUM6.5Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured fo...
CVE-2025-47792MEDIUM6.1Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty app...
CVE-2025-47791MEDIUM5.3Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and N...
CVE-2025-47790MEDIUM6.4Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextc...
CVE-2025-32962MEDIUM6.1Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for ...
CVE-2025-40907MEDIUM5.3FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The in...
CVE-2025-2306MEDIUM5.9An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows us...
CVE-2025-40632MEDIUM6.1Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to mod...
CVE-2025-40631MEDIUM6.1HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header a...
CVE-2025-40630MEDIUM6.1Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to...
CVE-2025-4768MEDIUM6.3A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects...
CVE-2025-4767MEDIUM5.3A vulnerability was found in defog-ai introspect up to 0.1.4. It has been rated as critical. Affected by this issue is t...
CVE-2025-4679MEDIUM6.5A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive in...
CVE-2025-4755MEDIUM5.3A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been classified as critical. This affects the...
CVE-2025-4753MEDIUM6.9A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this issue...
CVE-2025-3624MEDIUM4.3Missing Authorization vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).T...
CVE-2025-1531MEDIUM6.5Authentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint.This issue affects Hitachi Op...
CVE-2025-4752MEDIUM6.9A vulnerability has been found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this ...
CVE-2025-4750MEDIUM6.9A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). This issu...
CVE-2025-3516MEDIUM5.9The Simple Lightbox WordPress plugin before 2.9.4 does not validate and escape some of its attributes before outputting ...
CVE-2025-3201MEDIUM5.9The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some...
CVE-2025-1245MEDIUM6.5Bypass Connection Restriction vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component...
CVE-2025-4759MEDIUM5.3Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now