2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-39932MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb: client: let smbd_destroy() call disable_work_s...
CVE-2025-39931MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_...
CVE-2025-39929MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_neg...
CVE-2025-9952MEDIUM6.1The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to R...
CVE-2025-9886MEDIUM4.3The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to C...
CVE-2025-10383MEDIUM6.4The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-9030MEDIUM5.4The Majestic Before After Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_label'...
CVE-2025-9029MEDIUM4.3The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPres...
CVE-2025-8726MEDIUM5.4The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including,...
CVE-2025-61962MEDIUM5.9In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed...
CVE-2025-11228MEDIUM5.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2025-11227MEDIUM6.5The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all ...
CVE-2025-10746MEDIUM6.5The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and incl...
CVE-2025-61685MEDIUM6.5Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vuln...
CVE-2025-61681MEDIUM5.4KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its fi...
CVE-2025-61680MEDIUM6.6Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0....
CVE-2025-43825MEDIUM6.5A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 throug...
CVE-2025-10696MEDIUM5.4OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does no...
CVE-2025-10695MEDIUM5.3Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied d...
CVE-2025-59829MEDIUM6.5Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission de...
CVE-2025-53354MEDIUM6.1NiceGUI is a Python-based UI framework. Versions 2.24.2 and below are at risk for Cross-Site Scripting (XSS) when develo...
CVE-2025-54154MEDIUM6.8An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical a...
CVE-2025-53407MEDIUM6.5A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2025-53406MEDIUM6.5A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2025-52867MEDIUM6.5An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now