2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-30168MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 a...
CVE-2025-2598MEDIUM5.7When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which...
CVE-2025-2593MEDIUM6.3A vulnerability has been found in FastCMS up to 0.1.5 and classified as critical. Affected by this vulnerability is an u...
CVE-2025-29640MEDIUM5.4Phpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-repo...
CVE-2025-27612MEDIUM5.9libcontainer is a library for container control. Prior to libcontainer 0.5.3, while creating a tenant container, the ten...
CVE-2025-2591MEDIUM5.5A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affect...
CVE-2025-2590MEDIUM5.4A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic...
CVE-2025-2597MEDIUM6.1Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5.5.5.2-b3526 from Impact Technologies. This vulnerability co...
CVE-2025-2587MEDIUM6.3A vulnerability, which was classified as critical, was found in Jinher OA C6 1.0. This affects an unknown part of the fi...
CVE-2025-30179MEDIUM6.5Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, whi...
CVE-2025-27933MEDIUM4.3Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion rest...
CVE-2025-24920MEDIUM4.3Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark cre...
CVE-2025-2584MEDIUM6.8A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the f...
CVE-2025-30348MEDIUM5.3encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts ...
CVE-2025-30346MEDIUM4.8Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.
CVE-2025-2583MEDIUM6.1A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown pa...
CVE-2025-2582MEDIUM5.4A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unkn...
CVE-2025-30345MEDIUM4.1An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user i...
CVE-2025-30343MEDIUM6.5A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and ...
CVE-2025-30342MEDIUM6.1An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda T...
CVE-2025-2557MEDIUM5.5A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is som...
CVE-2025-29218MEDIUM6.5Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. T...
CVE-2025-29217MEDIUM6.5Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. ...
CVE-2025-2556MEDIUM5.3A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. Affected by this vulnerability is an unknow...
CVE-2025-2553MEDIUM5.3A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been rated as problematic. This issue affects...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now