2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-69230MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading mu...
CVE-2025-69229MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling o...
CVE-2025-69225MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser...
CVE-2025-69226MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an atta...
CVE-2025-69224MEDIUM6.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python ...
CVE-2025-68437MEDIUM6.8Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16...
CVE-2025-68436MEDIUM6.5Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16...
CVE-2025-67732MEDIUM6.5Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the...
CVE-2025-66648MEDIUM6.1vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites tha...
CVE-2025-61916MEDIUM6.6Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3....
CVE-2025-64422MEDIUM4.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting...
CVE-2025-67427MEDIUM6.5A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to...
CVE-2025-52517MEDIUM5.9An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-52516MEDIUM6.2An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-52515MEDIUM5.1An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, ...
CVE-2025-65922MEDIUM4.3PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malic...
CVE-2025-59955MEDIUM5.7Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri...
CVE-2025-67316MEDIUM5.4An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage...
CVE-2025-53344MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in ThimPress Thim Core allows Cross Site Request Forgery.This issue affe...
CVE-2025-39561MEDIUM6.5Missing Authorization vulnerability in Marketing Fire, LLC LoginWP - Pro allows Accessing Functionality Not Properly Con...
CVE-2025-39497MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro al...
CVE-2025-10933MEDIUM5.3An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads...
CVE-2025-65328MEDIUM6.5Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client I...
CVE-2025-66376MEDIUM6.1Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sh...
CVE-2025-68280MEDIUM6.5Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now