2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-39908MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: dev_ioctl: take ops lock in hwtstamp lower pat...
CVE-2025-39907MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: stm32_fmc2: avoid overlapping mapping...
CVE-2025-39906MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: remove oem i2c adapter on finish ...
CVE-2025-39904MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64: kexec: initialize kexec_buf struct in load_o...
CVE-2025-39903MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: of_numa: fix uninitialized memory nodes causing ker...
CVE-2025-39902MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is i...
CVE-2025-39900MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net_sched: gen_estimator: fix est_timer() vs CONFIG...
CVE-2025-39899MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/userfaultfd: fix kmap_local LIFO ordering for CO...
CVE-2025-39897MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Add error handling for RX met...
CVE-2025-39895MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched: Fix sched_numa_find_nth_cpu() if mask offlin...
CVE-2025-39894MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit...
CVE-2025-39893MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: unregister ECC engine on probe...
CVE-2025-39892MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: care NULL dirver name on snd_soc_lo...
CVE-2025-9512MEDIUM6.1The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modi...
CVE-2025-9075MEDIUM6.4The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versio...
CVE-2025-10744MEDIUM5.9The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposu...
CVE-2025-10735MEDIUM4The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Reques...
CVE-2025-61792MEDIUM6.4Quadient DS-700 iQ devices through 2025-09-30 might have a race condition during the quick clicking of (in order) the Qu...
CVE-2025-55191MEDIUM5.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1,...
CVE-2025-43826MEDIUM5.4Stored cross-site scripting (XSS) vulnerabilities in Web Content translation in Liferay Portal 7.4.0 through 7.4.3.112, ...
CVE-2025-36262MEDIUM4.9IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to...
CVE-2025-36132MEDIUM5.4IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 is vulnerable to cross-site scripting. This ...
CVE-2025-43827MEDIUM4.3Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and o...
CVE-2025-57254MEDIUM6.5An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allo...
CVE-2025-56200MEDIUM6.1A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now