2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-68365MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use K...
CVE-2025-68358MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix racy bitfield write in btrfs_clear_space...
CVE-2025-68351MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: exfat: fix refcount leak in exfat_find Fix refcoun...
CVE-2025-64641MEDIUM4.1Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post ...
CVE-2025-13767MEDIUM4.3Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user ch...
CVE-2025-13407MEDIUM6.8The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files throug...
CVE-2025-15052MEDIUM5.4A vulnerability was detected in code-projects Student Information System 1.0. This vulnerability affects unknown code of...
CVE-2025-14421MEDIUM5.5pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allo...
CVE-2025-14411MEDIUM5.5Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem...
CVE-2025-14410MEDIUM5.5Soda PDF Desktop PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem...
CVE-2025-14407MEDIUM5.5Soda PDF Desktop PDF File Parsing Memory Corruption Information Disclosure Vulnerability. This vulnerability allows remo...
CVE-2025-14405MEDIUM6.8PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phy...
CVE-2025-13698MEDIUM4.5Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability a...
CVE-2025-65713MEDIUM4Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully val...
CVE-2025-65410MEDIUM6.2A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-45493MEDIUM6.5Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.
CVE-2025-68340MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of te...
CVE-2025-66845MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoin...
CVE-2025-68559MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem...
CVE-2025-68557MEDIUM4.3Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Acc...
CVE-2025-68556MEDIUM5.3Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect...
CVE-2025-68551MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form...
CVE-2025-68548MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Res...
CVE-2025-14635MEDIUM6.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom...
CVE-2025-14000MEDIUM6.4The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now