2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2278MEDIUM6.5Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and...
CVE-2025-1636MEDIUM6.5Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Ma...
CVE-2025-1635MEDIUM6.5Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and ...
CVE-2025-21104MEDIUM6.5Dell NetWorker, versions prior to 19.11.0.4 and version 19.12, contains an URL Redirection to Untrusted Site ('Open Redi...
CVE-2025-0652MEDIUM6.5An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions start...
CVE-2025-2104MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized post publ...
CVE-2025-1561MEDIUM6.1The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' ...
CVE-2025-1503MEDIUM6.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Roundup Recipe Name field ...
CVE-2025-2250MEDIUM4.9The WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins plugin for WordPress is vulnerable t...
CVE-2025-1559MEDIUM6.4The CC-IMG-Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'img' shortcode ...
CVE-2025-22870MEDIUM4.4Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when...
CVE-2025-0116MEDIUM6.8A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot...
CVE-2025-0115MEDIUM6.8A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbit...
CVE-2025-27017MEDIUM6.5Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi proven...
CVE-2025-25774MEDIUM6.5An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specifi...
CVE-2025-25683MEDIUM5.6AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects Ale...
CVE-2025-2002MEDIUM6CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP s...
CVE-2025-27867MEDIUM5.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP ...
CVE-2025-25566MEDIUM5.6Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAl...
CVE-2025-20177MEDIUM6.7A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisc...
CVE-2025-20145MEDIUM5.8A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow...
CVE-2025-20144MEDIUM5.8A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow ...
CVE-2025-20143MEDIUM6.7A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv...
CVE-2025-1984MEDIUM5.2Xerox Desktop Print Experience application contains a Local Privilege Escalation (LPE) vulnerability, which allows a low...
CVE-2025-29891MEDIUM4.8Bypass/Injection vulnerability in Apache Camel. This issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now