2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-21259MEDIUM5.3Microsoft Outlook Spoofing Vulnerability
CVE-2025-21254MEDIUM6.5Internet Connection Sharing (ICS) Denial of Service Vulnerability
CVE-2025-21216MEDIUM6.5Internet Connection Sharing (ICS) Denial of Service Vulnerability
CVE-2025-21212MEDIUM6.5Internet Connection Sharing (ICS) Denial of Service Vulnerability
CVE-2025-21188MEDIUM6Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
CVE-2025-21179MEDIUM4.8DHCP Client Service Denial of Service Vulnerability
CVE-2025-21162MEDIUM5.5Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect ...
CVE-2025-21155MEDIUM5.5Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could resu...
CVE-2025-21126MEDIUM5.5InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that c...
CVE-2025-21125MEDIUM5.5InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that cou...
CVE-2025-21124MEDIUM5.5InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could le...
CVE-2025-24976MEDIUM6.6Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-b...
CVE-2025-26493MEDIUM6.1In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
CVE-2025-1231MEDIUM5.4Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reus...
CVE-2025-0588MEDIUM4.9In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all se...
CVE-2025-24532MEDIUM5.3A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1...
CVE-2025-0862MEDIUM4.9The SuperSaaS – online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2025-0526MEDIUM5.4In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API ...
CVE-2025-0513MEDIUM5.4In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could con...
CVE-2025-26409MEDIUM6.8A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the ...
CVE-2025-26408MEDIUM6.1The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the ...
CVE-2025-1182MEDIUM5A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_relo...
CVE-2025-0589MEDIUM5.3In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for...
CVE-2025-1181MEDIUM5A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_...
CVE-2025-1178MEDIUM6.3A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now