2025 CVE Vulnerabilities

45,160 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67418CRITICAL9.8ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded...
CVE-2025-67291MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute a...
CVE-2025-67290MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to e...
CVE-2025-65837MEDIUM5.4PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.
CVE-2025-65790MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file ...
CVE-2025-67288CRITICAL10An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a ...
CVE-2025-63664HIGH7.5Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows un...
CVE-2025-63663HIGH7.5Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthori...
CVE-2025-63662HIGH7.5Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers t...
CVE-2025-26787MEDIUM4.7An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CL...
CVE-2025-15033MEDIUM6.5A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on si...
CVE-2025-68645HIGH8.8A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 ...
CVE-2025-67289CRITICAL9.6An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execut...
CVE-2025-65270MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote ...
CVE-2025-68337HIGH7.5In the Linux kernel, the following vulnerability has been resolved: jbd2: avoid bug_on in jbd2_journal_get_create_acces...
CVE-2025-68336HIGH7.5In the Linux kernel, the following vulnerability has been resolved: locking/spinlock/debug: Fix data-race in do_raw_wri...
CVE-2025-68335In the Linux kernel, the following vulnerability has been resolved: comedi: pcl818: fix null-ptr-deref in pcl818_ai_can...
CVE-2025-68334In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Add support for Van Gogh SoC ...
CVE-2025-68333MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix possible deadlock in the deferred_ir...
CVE-2025-68332In the Linux kernel, the following vulnerability has been resolved: comedi: c6xdigio: Fix invalid PNP driver unregistra...
CVE-2025-68331In the Linux kernel, the following vulnerability has been resolved: usb: uas: fix urb unmapping issue when the uas devi...
CVE-2025-68330In the Linux kernel, the following vulnerability has been resolved: iio: accel: bmc150: Fix irq assumption regression ...
CVE-2025-68329In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close ...
CVE-2025-68328In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: fix bug in saving controll...
CVE-2025-68327In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Fix synchronous external abort ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now