2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2770MEDIUM6.5BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability al...
CVE-2025-2763MEDIUM6.8CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability ...
CVE-2025-29526MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allow...
CVE-2025-28017MEDIUM6.5TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING param...
CVE-2025-1522MEDIUM6.5PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remo...
CVE-2025-1521MEDIUM6.5PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allo...
CVE-2025-46393MEDIUM5.3In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the renderi...
CVE-2025-43716MEDIUM5.8A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to...
CVE-2025-2703MEDIUM6.8The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modif...
CVE-2025-42604MEDIUM6.9This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker...
CVE-2025-1054MEDIUM6.4The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2025-2595MEDIUM5.3An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization templa...
CVE-2025-0618MEDIUM6.5A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a spec...
CVE-2025-1056MEDIUM6.5Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the ...
CVE-2025-37088MEDIUM6.8A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions...
CVE-2025-27087MEDIUM5.5A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Se...
CVE-2025-29743MEDIUM6.5D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.
CVE-2025-26159MEDIUM6.1Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of cr...
CVE-2025-31328MEDIUM4.6SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated us...
CVE-2025-31327MEDIUM4.3SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which ...
CVE-2025-43952MEDIUM6.1A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0...
CVE-2025-32964MEDIUM4.6ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 00bebea, when enabling a conflicting...
CVE-2025-32963MEDIUM6.9MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided f...
CVE-2025-32961MEDIUM6.4The Cuba JPA web API enables loading and saving any entities defined in the application data model by sending simple HTT...
CVE-2025-32960MEDIUM6.4The CUBA REST API add-on performs operations on data and entities. Prior to version 7.2.7, the input parameter, which co...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now