2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-3382MEDIUM6.3A vulnerability has been found in joey-zhou xiaozhi-esp32-server-java up to a14fe8115842ee42ab5c7a51706b8a85db5200b7 and...
CVE-2025-29769MEDIUM5.5libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly de...
CVE-2025-29594MEDIUM6.1A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is n...
CVE-2025-29482MEDIUM6.2Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Ad...
CVE-2025-29481MEDIUM6.2Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init...
CVE-2025-29480MEDIUM5.5Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialRefe...
CVE-2025-29478MEDIUM5.5An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:...
CVE-2025-28401MEDIUM6.7An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
CVE-2025-28400MEDIUM6.7An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
CVE-2025-32014MEDIUM6.9estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value ...
CVE-2025-31476MEDIUM4.8tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowi...
CVE-2025-31475MEDIUM6.6tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior t...
CVE-2025-31138MEDIUM6.6tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior t...
CVE-2025-30373MEDIUM5.3Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a speci...
CVE-2025-2251MEDIUM6.2A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) ...
CVE-2025-27686MEDIUM4.7Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an...
CVE-2025-3359MEDIUM6.2A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.
CVE-2025-0050MEDIUM5.9Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace D...
CVE-2025-21431MEDIUM4.7Information disclosure may be there when a guest VM is connected.
CVE-2025-31173MEDIUM6.5Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerab...
CVE-2025-31172MEDIUM5.5Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerab...
CVE-2025-31171MEDIUM5.5File read permission bypass vulnerability in the kernel file system module Impact: Successful exploitation of this vulne...
CVE-2025-20662MEDIUM6.7In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalati...
CVE-2025-20661MEDIUM6.7In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalati...
CVE-2025-20660MEDIUM6.7In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalati...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now