2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-24887MEDIUM6.3OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allo...
CVE-2025-4135MEDIUM6.3A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the funct...
CVE-2025-24091MEDIUM5.5An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue i...
CVE-2025-3859MEDIUM6.1Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating be...
CVE-2025-32972MEDIUM5.3XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to befo...
CVE-2025-32970MEDIUM6.1XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16....
CVE-2025-32376MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the bet...
CVE-2025-45021MEDIUM5.3A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management...
CVE-2025-45019MEDIUM5.4A SQL injection vulnerability was discovered in /add-foreigners-ticket.php file of PHPGurukul Park Ticketing Management ...
CVE-2025-45015MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGuruku...
CVE-2025-45011MEDIUM5.3A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management S...
CVE-2025-45010MEDIUM5.3A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketin...
CVE-2025-45009MEDIUM5.3A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management Syst...
CVE-2025-45007MEDIUM4.8A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the profile.php file of PHPGurukul Timetable Gene...
CVE-2025-3395MEDIUM5.5Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB A...
CVE-2025-27532MEDIUM6.5A vulnerability in the “Backup & Restore” functionality of the web application of ctrlX OS allows a remote authenticated...
CVE-2025-24348MEDIUM5.4A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticat...
CVE-2025-24347MEDIUM6.5A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticat...
CVE-2025-24345MEDIUM6.3A vulnerability in the “Hosts” functionality of the web application of ctrlX OS allows a remote authenticated (low-privi...
CVE-2025-24344MEDIUM6.3A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated at...
CVE-2025-24343MEDIUM5.4A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated...
CVE-2025-24342MEDIUM5.3A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker t...
CVE-2025-24341MEDIUM6.5A vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to induce a D...
CVE-2025-24340MEDIUM6.5A vulnerability in the users configuration file of ctrlX OS may allow a remote authenticated (low-privileged) attacker t...
CVE-2025-24339MEDIUM5A vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now