2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-68160MEDIUM4.7Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO perf...
CVE-2025-66199MEDIUM5.9Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp...
CVE-2025-28164MEDIUM5.5Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_creat...
CVE-2025-28162MEDIUM5.5Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngim...
CVE-2025-15469MEDIUM5.5Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing al...
CVE-2025-15468MEDIUM5.9Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un...
CVE-2025-11187MEDIUM6.1Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow...
CVE-2025-41728MEDIUM5.3A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged proces...
CVE-2025-12387MEDIUM6.9A vulnerability in the Pix-Link LV-WR21Q router's language module allows remote attackers to trigger a denial of service...
CVE-2025-12386MEDIUM6.9Pix-Link LV-WR21Q does not enforce any form of authentication for endpoint /goform/getHomePageInfo. Remote unauthenticat...
CVE-2025-14971MEDIUM5.3The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to ...
CVE-2025-9820MEDIUM4A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 tok...
CVE-2025-9522MEDIUM5.3Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests t...
CVE-2025-9521MEDIUM6.5Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa...
CVE-2025-9520MEDIUM6.8An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate r...
CVE-2025-14969MEDIUM4.3A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client...
CVE-2025-14525MEDIUM6.4A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by ca...
CVE-2025-11687MEDIUM6.1A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page —...
CVE-2025-11065MEDIUM5.3A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode...
CVE-2025-70368MEDIUM5.4Worklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An att...
CVE-2025-57785MEDIUM6.5A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticate...
CVE-2025-57783MEDIUM5.3Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allow...
CVE-2025-50537MEDIUM5.5Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/sha...
CVE-2025-59109MEDIUM5.1The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sendin...
CVE-2025-59102MEDIUM6.9The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now