2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-64105MEDIUM5.1FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online s...
CVE-2025-13162MEDIUM4.4Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affect...
CVE-2025-55639MEDIUM6.5GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomed...
CVE-2025-33128MEDIUM5.4IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerab...
CVE-2025-2669MEDIUM6.5IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a pri...
CVE-2025-62198MEDIUM5.4An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommend...
CVE-2025-71331MEDIUM6.1Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat ...
CVE-2025-15661MEDIUM6.5libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink()...
CVE-2025-32748MEDIUM6.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticate...
CVE-2025-15657MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.
CVE-2025-69137MEDIUM6.5Subscriber Broken Access Control in Genemy <= 1.6.6 versions.
CVE-2025-62340MEDIUM5.3HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where ...
CVE-2025-48571MEDIUM4.3In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic er...
CVE-2025-15642MEDIUM6.8Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with ad...
CVE-2025-15641MEDIUM6.8Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with ad...
CVE-2025-9912MEDIUM6.3Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerabilit...
CVE-2025-10262MEDIUM6.3Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successfu...
CVE-2025-69332MEDIUM6.5Subscriber Broken Access Control in Bookify <= 1.1.1 versions.
CVE-2025-68049MEDIUM6.3Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.
CVE-2025-60175MEDIUM4.4Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.
CVE-2025-70102MEDIUM6.3A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options....
CVE-2025-55663MEDIUM5.5A segmentation violation in the Track_SetStreamDescriptor function (isomedia/track.c) of GPAC MP4Box v2.4 allows attacke...
CVE-2025-55661MEDIUM5.5A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial ...
CVE-2025-55660MEDIUM5.5A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to ...
CVE-2025-55652MEDIUM5.5A heap buffer overflow in the gf_isom_vp_config_new function (isomedia/avc_ext.c) of GPAC MP4Box v2.4 allows attackers t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now