2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-39894MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit...
CVE-2025-39893MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: unregister ECC engine on probe...
CVE-2025-39892MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: care NULL dirver name on snd_soc_lo...
CVE-2025-9512MEDIUM6.1The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modi...
CVE-2025-9075MEDIUM6.4The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versio...
CVE-2025-10744MEDIUM5.9The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposu...
CVE-2025-10735MEDIUM4The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Reques...
CVE-2025-61792MEDIUM6.4Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Qu...
CVE-2025-55191MEDIUM5.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1,...
CVE-2025-43826MEDIUM5.4Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, ...
CVE-2025-36262MEDIUM4.9IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to...
CVE-2025-36132MEDIUM5.4IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This ...
CVE-2025-43827MEDIUM4.3Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and o...
CVE-2025-57254MEDIUM6.5An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allo...
CVE-2025-56200MEDIUM6.1A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' a...
CVE-2025-23292MEDIUM4.6NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Atta...
CVE-2025-56520MEDIUM5.3Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_...
CVE-2025-56207MEDIUM6.5A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Et...
CVE-2025-56676MEDIUM5.4TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary p...
CVE-2025-56018MEDIUM6.1SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category...
CVE-2025-55797MEDIUM6.5An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauth...
CVE-2025-54477MEDIUM5.3Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.
CVE-2025-54476MEDIUM4.8Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.
CVE-2025-57852MEDIUM6.4A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/pas...
CVE-2025-28016MEDIUM4.8A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Re...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now