2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30665MEDIUM6.5NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of ...
CVE-2025-47709MEDIUM6.5Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affect...
CVE-2025-47706MEDIUM4.8Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services w...
CVE-2025-47705MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remo...
CVE-2025-47704MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cooki...
CVE-2025-47703MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con...
CVE-2025-47702MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal oEmbed Prov...
CVE-2025-44186MEDIUM5.4SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operatio...
CVE-2025-44184MEDIUM4.8SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi...
CVE-2025-3932MEDIUM6.5It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attach...
CVE-2025-26784MEDIUM6.5An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-47778MEDIUM6.1Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5,...
CVE-2025-24969MEDIUM5iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts pictur...
CVE-2025-24785MEDIUM4.3iTop is an web based IT Service Management tool. In version 3.2.0, an attacker may send a URL to the server to trigger a...
CVE-2025-24026MEDIUM5.3iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of ...
CVE-2025-24021MEDIUM5iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account havi...
CVE-2025-3769MEDIUM5.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc...
CVE-2025-4520MEDIUM4.3The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2025-4574MEDIUM6.5In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some c...
CVE-2025-47905MEDIUM5.4Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via H...
CVE-2025-43566MEDIUM6.8ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restr...
CVE-2025-43551MEDIUM5.5Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to d...
CVE-2025-30316MEDIUM5.4Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be ...
CVE-2025-30315MEDIUM6.1Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be ...
CVE-2025-30314MEDIUM6.1Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now