2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22720MEDIUM5.8Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme...
CVE-2025-22265MEDIUM6.5Missing Authorization vulnerability in mgplugin EMI Calculator emi-calculator allows Exploiting Incorrectly Configured A...
CVE-2025-22216MEDIUM5.4A UAA configured with multiple identity zones, does not properly validate session information across those zones. A Use...
CVE-2025-0507MEDIUM6.4The Ticketmeo – Sell Tickets – Event Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-0470MEDIUM6.1The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected ...
CVE-2025-0573MEDIUM5.3Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows rem...
CVE-2025-0572MEDIUM4.3Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability...
CVE-2025-0571MEDIUM6.5Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allo...
CVE-2025-0570MEDIUM6.5Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allo...
CVE-2025-0146MEDIUM5Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to con...
CVE-2025-0144MEDIUM6.5Out-of-bounds write in some Zoom Workplace Apps may allow an authorized user to conduct a loss of integrity via network ...
CVE-2025-0143MEDIUM6.5Out-of-bounds write in the Zoom Workplace App for Linux before version 6.2.5 may allow an unauthorized user to conduct a...
CVE-2025-0142MEDIUM4.3Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authen...
CVE-2025-24506MEDIUM5.3A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
CVE-2025-24504MEDIUM5.3An improper input validation the CSRF filter results in unsanitized user input written to the application logs.
CVE-2025-24502MEDIUM5.3An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed ...
CVE-2025-24501MEDIUM5.3An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP re...
CVE-2025-0681MEDIUM6.9The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to o...
CVE-2025-24099MEDIUM5.1The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Vent...
CVE-2025-0367MEDIUM6.5In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnera...
CVE-2025-24784MEDIUM4.3kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. ...
CVE-2025-24376MEDIUM6.5kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. ...
CVE-2025-23216MEDIUM6.8Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that...
CVE-2025-22222MEDIUM6.5VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privil...
CVE-2025-22221MEDIUM4.8VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privil...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now