2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-28096MEDIUM5.4OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
CVE-2025-28094MEDIUM6.5shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
CVE-2025-28093MEDIUM6.3ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.
CVE-2025-28092MEDIUM6.3ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.
CVE-2025-28254MEDIUM5.4Cross Site Scripting vulnerability in Leantime v3.2.1 and before allows an authenticated attacker to execute arbitrary c...
CVE-2025-2926MEDIUM5.5A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache...
CVE-2025-2925MEDIUM5.5A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the functi...
CVE-2025-2924MEDIUM5.5A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl...
CVE-2025-31164MEDIUM6.6heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via  c...
CVE-2025-31163MEDIUM6.6Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_...
CVE-2025-31162MEDIUM6.6Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation vi...
CVE-2025-2921MEDIUM6.4A vulnerability classified as critical has been found in Netis WF-2404 1.1.124EN. Affected is an unknown function of the...
CVE-2025-2916MEDIUM6.3A vulnerability, which was classified as critical, has been found in Aishida Call Center System up to 20250314. This iss...
CVE-2025-2915MEDIUM5.5A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__a...
CVE-2025-2913MEDIUM5.3A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5...
CVE-2025-2912MEDIUM5.3A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is t...
CVE-2025-31010MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ReichertBrothers SimplyRETS Real Estate IDX simply-rets allows Cross ...
CVE-2025-2877MEDIUM6.5A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to ...
CVE-2025-2865MEDIUM6.1SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web...
CVE-2025-2864MEDIUM6.1SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning ...
CVE-2025-2860MEDIUM5.3SaTECH BCU in its firmware version 2.1.3, allows an authenticated attacker to access information about the credentials t...
CVE-2025-1781MEDIUM6.5There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML o...
CVE-2025-0986MEDIUM4.4IBM PowerVM Hypervisor FW1050.00 through FW1050.30 and FW1060.00 through FW1060.20 could allow a local user, under certa...
CVE-2025-2911MEDIUM5.3Unauthorised access to the call forwarding service system in MeetMe products in versions prior to 2024-09 allows an atta...
CVE-2025-2910MEDIUM6.9User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now