2025 CVE Vulnerabilities

45,264 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-38097MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: espintcp: remove encap socket caching to avoid refe...
CVE-2025-38096MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: don't warn when if there is a FW err...
CVE-2025-38095MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_...
CVE-2025-38094MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: cadence: macb: Fix a possible deadlock in macb...
CVE-2025-5944MEDIUM5.4The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-ca...
CVE-2025-52842MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Laundry on ...
CVE-2025-52559MEDIUM5.4Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL ...
CVE-2025-43025HIGH7.5HP Universal Print Driver is potentially vulnerable to denial of service due to buffer overflow in versions of UPD 7.4 o...
CVE-2025-34092Rejected reason: Neither filed by Chrome nor a valid security vulnerability.
CVE-2025-34091Rejected reason: Neither filed by Chrome nor a valid security vulnerability.
CVE-2025-34090Rejected reason: Neither filed by Chrome nor a valid security vulnerability.
CVE-2025-34079HIGH7.8An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and Ex...
CVE-2025-34078HIGH7.8A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web interface and ExternalScripts...
CVE-2025-34076HIGH7.2An authenticated local file inclusion vulnerability exists in Microweber CMS versions <= 1.2.11 through misuse of the ba...
CVE-2025-34075Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Initially assigned to docum...
CVE-2025-34074CRITICAL9.4An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design i...
CVE-2025-49713HIGH8.8Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2025-45813CRITICAL9.8ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
CVE-2025-52841HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This i...
CVE-2025-45814CRITICAL9.8Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v...
CVE-2025-45424MEDIUM5.3Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.
CVE-2025-20309CRITICAL10A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma...
CVE-2025-20307MEDIUM4.8A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an ...
CVE-2025-6943MEDIUM4Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator...
CVE-2025-6942LOW3.8The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited duri...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now