2025 CVE Vulnerabilities

45,160 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-48864Rejected reason: This CVE id was assigned but later discarded.
CVE-2025-48863Rejected reason: This CVE id was assigned but later discarded.
CVE-2025-45493MEDIUM6.5Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.
CVE-2025-68343In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check ...
CVE-2025-68342In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): check ...
CVE-2025-68341CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix ra...
CVE-2025-68340MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: team: Move team device type change at the end of te...
CVE-2025-68339In the Linux kernel, the following vulnerability has been resolved: atm/fore200e: Fix possible data race in fore200e_op...
CVE-2025-68338In the Linux kernel, the following vulnerability has been resolved: net: dsa: microchip: Don't free uninitialized ksz_i...
CVE-2025-66845MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoin...
CVE-2025-13183HIGH7.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hotech Soft...
CVE-2025-68561HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia Autom...
CVE-2025-68560HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68559MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem...
CVE-2025-68557MEDIUM4.3Missing Authorization vulnerability in Vikas Ratudi Chakra test chakra-test allows Exploiting Incorrectly Configured Acc...
CVE-2025-68556MEDIUM5.3Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrect...
CVE-2025-68551MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vikas Ratudi VPSUForm v-form...
CVE-2025-68550HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky...
CVE-2025-68548MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Res...
CVE-2025-68546HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68544HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-59886HIGH8.8Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker w...
CVE-2025-14635MEDIUM6.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom...
CVE-2025-14000MEDIUM6.4The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2025-14548MEDIUM6.4The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all ver...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now