2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39894 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit... |
| CVE-2025-39893 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: unregister ECC engine on probe... |
| CVE-2025-39892 | MEDIUM | 5.5 | 0.1% | Oct 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: care NULL dirver name on snd_soc_lo... |
| CVE-2025-9512 | MEDIUM | 6.1 | 0.2% | Oct 1, 2025 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modi... |
| CVE-2025-9075 | MEDIUM | 6.4 | 0.2% | Oct 1, 2025 | The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versio... |
| CVE-2025-10744 | MEDIUM | 5.9 | 0.4% | Oct 1, 2025 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposu... |
| CVE-2025-10735 | MEDIUM | 4 | 0.3% | Oct 1, 2025 | The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Reques... |
| CVE-2025-61792 | MEDIUM | 6.4 | 0.1% | Sep 30, 2025 | Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Qu... |
| CVE-2025-55191 | MEDIUM | 5.3 | 0.4% | Sep 30, 2025 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1,... |
| CVE-2025-43826 | MEDIUM | 5.4 | 0.2% | Sep 30, 2025 | Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, ... |
| CVE-2025-36262 | MEDIUM | 4.9 | 0.3% | Sep 30, 2025 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to... |
| CVE-2025-36132 | MEDIUM | 5.4 | 0.2% | Sep 30, 2025 | IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This ... |
| CVE-2025-43827 | MEDIUM | 4.3 | 0.3% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and o... |
| CVE-2025-57254 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allo... |
| CVE-2025-56200 | MEDIUM | 6.1 | 0.3% | Sep 30, 2025 | A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' a... |
| CVE-2025-23292 | MEDIUM | 4.6 | 0.2% | Sep 30, 2025 | NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Atta... |
| CVE-2025-56520 | MEDIUM | 5.3 | 0.6% | Sep 30, 2025 | Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_... |
| CVE-2025-56207 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Et... |
| CVE-2025-56676 | MEDIUM | 5.4 | 0.3% | Sep 30, 2025 | TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary p... |
| CVE-2025-56018 | MEDIUM | 6.1 | 0.2% | Sep 30, 2025 | SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category... |
| CVE-2025-55797 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauth... |
| CVE-2025-54477 | MEDIUM | 5.3 | 0.3% | Sep 30, 2025 | Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method. |
| CVE-2025-54476 | MEDIUM | 4.8 | 0.3% | Sep 30, 2025 | Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class. |
| CVE-2025-57852 | MEDIUM | 6.4 | 0.1% | Sep 30, 2025 | A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/pas... |
| CVE-2025-28016 | MEDIUM | 4.8 | 0.2% | Sep 30, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Re... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now