2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1158MEDIUM6.3A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unk...
CVE-2025-1157MEDIUM6.3A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknow...
CVE-2025-1002MEDIUM5.3MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it...
CVE-2025-1155MEDIUM6.1A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of...
CVE-2025-1154MEDIUM6.3A vulnerability, which was classified as critical, has been found in xxyopen Novel up to 3.4.1. Affected by this issue i...
CVE-2025-24200MEDIUM6.1An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4...
CVE-2025-1153MEDIUM5.9A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the fun...
CVE-2025-25188MEDIUM5.7Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prio...
CVE-2025-25186MEDIUM6.5Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and...
CVE-2025-24892MEDIUM5.4OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to...
CVE-2025-24031MEDIUM5.1PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. In versions 0.6.12 and prior, ...
CVE-2025-21691MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cachestat: fix page cache statistics permission che...
CVE-2025-21690MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM...
CVE-2025-21689MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: USB: serial: quatech2: fix null-ptr-deref in qt2_pr...
CVE-2025-21688MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Assign job pointer to NULL before signalin...
CVE-2025-1147MEDIUM5.3A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the...
CVE-2025-1175MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Kelio Visio 1, Kelio Visio X7 and Kelio Visio X4, in versions betw...
CVE-2025-25247MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webco...
CVE-2025-21685MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger...
CVE-2025-21684MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gpio: xilinx: Convert gpio_lock to raw spinlock ir...
CVE-2025-0169MEDIUM5.4The DWT - Directory & Listing WordPress Theme is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up...
CVE-2025-1115MEDIUM5.5A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the func...
CVE-2025-25187MEDIUM5.4Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into...
CVE-2025-1114MEDIUM5.4A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /...
CVE-2025-24980MEDIUM5.3pimcore/admin-ui-classic-bundle provides a Backend UI for Pimcore. In affected versions an error message discloses exist...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now