2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-27379MEDIUM4.6A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker...
CVE-2025-27377MEDIUM5.3Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capa...
CVE-2025-69285MEDIUM6.1SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a mi...
CVE-2025-69209MEDIUM6.9ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in ...
CVE-2025-68140MEDIUM4.3EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has b...
CVE-2025-68139MEDIUM4.3EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminat...
CVE-2025-68138MEDIUM4.7EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol....
CVE-2025-13465MEDIUM5.3Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An atta...
CVE-2025-12781MEDIUM5.3When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the...
CVE-2025-68135MEDIUM6.5EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by...
CVE-2025-68132MEDIUM4.6EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermet...
CVE-2025-57681MEDIUM5.4The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-j...
CVE-2025-14559MEDIUM6.5A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and re...
CVE-2025-58742MEDIUM5.9Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability ...
CVE-2025-58740MEDIUM5.5The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirecto...
CVE-2025-15367MEDIUM5.9The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigati...
CVE-2025-15366MEDIUM5.9The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigat...
CVE-2025-15282MEDIUM6User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL ...
CVE-2025-11468MEDIUM5.7When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not b...
CVE-2025-55132MEDIUM5.3A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` ev...
CVE-2025-66803MEDIUM4.8Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when d...
CVE-2025-67263MEDIUM6.1Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients m...
CVE-2025-67261MEDIUM6.5Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in t...
CVE-2025-33231MEDIUM6.7NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker ...
CVE-2025-67824MEDIUM6.1The WorklogPRO - Jira Timesheets plugin in the Jira Data Center before 4.24.2-jira9, 4.24.2-jira10 and 4.24.2-jira11 all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now