2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-20762MEDIUM6.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,...
CVE-2025-20761MEDIUM6.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,...
CVE-2025-20760MEDIUM6.5In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote de...
CVE-2025-69197MEDIUM6.5Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multip...
CVE-2025-68954MEDIUM5.4Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP co...
CVE-2025-69230MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading mu...
CVE-2025-69229MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling o...
CVE-2025-69225MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser...
CVE-2025-69226MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an atta...
CVE-2025-69224MEDIUM6.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python ...
CVE-2025-68437MEDIUM6.8Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16...
CVE-2025-68436MEDIUM6.5Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16...
CVE-2025-67732MEDIUM6.5Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the...
CVE-2025-66648MEDIUM6.1vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites tha...
CVE-2025-61916MEDIUM6.6Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3....
CVE-2025-64422MEDIUM4.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting...
CVE-2025-67427MEDIUM6.5A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to...
CVE-2025-52517MEDIUM5.9An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-52516MEDIUM6.2An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-52515MEDIUM5.1An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-65922MEDIUM4.3PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malic...
CVE-2025-59955MEDIUM5.7Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri...
CVE-2025-67316MEDIUM5.4An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage...
CVE-2025-53344MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ThimPress Thim Core allows Cross Site Request Forgery.This issue affe...
CVE-2025-39561MEDIUM6.5Missing Authorization vulnerability in Marketing Fire, LLC LoginWP - Pro allows Accessing Functionality Not Properly Con...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now