2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22220MEDIUM5.4VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative...
CVE-2025-23367MEDIUM6.5A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control manageme...
CVE-2025-0871MEDIUM5.3A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/a...
CVE-2025-0870MEDIUM5.9A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is ...
CVE-2025-0869MEDIUM5.3A vulnerability was found in Cianet ONU GW24AC up to 20250127. It has been declared as problematic. Affected by this vul...
CVE-2025-0747MEDIUM5.4A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attack...
CVE-2025-0746MEDIUM5.4A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an aut...
CVE-2025-0745MEDIUM6.5An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic...
CVE-2025-0744MEDIUM6.5an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic...
CVE-2025-0743MEDIUM4.3An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic...
CVE-2025-0742MEDIUM6.5An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic...
CVE-2025-0741MEDIUM4.3An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authent...
CVE-2025-0740MEDIUM6.5An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authent...
CVE-2025-0739MEDIUM6.5An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic...
CVE-2025-23007MEDIUM5.5A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows sy...
CVE-2025-0860MEDIUM6.1The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several ...
CVE-2025-23374MEDIUM4.9Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Se...
CVE-2025-0662MEDIUM4.9In some cases, the ktrace facility will log the contents of kernel structures to userspace. In one such case, ktrace du...
CVE-2025-0374MEDIUM6.5When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcup...
CVE-2025-0373MEDIUM6On 64-bit systems, the implementation of VOP_VPTOFH() in the cd9660, tarfs and ext2fs filesystems overflows the destinat...
CVE-2025-0844MEDIUM6.1A vulnerability was found in needyamin Library Card System 1.0. It has been declared as problematic. Affected by this vu...
CVE-2025-24884MEDIUM5.1kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vec...
CVE-2025-24795MEDIUM5.5The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak...
CVE-2025-24788MEDIUM5.5snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the ...
CVE-2025-24882MEDIUM5.2regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned m...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now