2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-39890MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_rea...
CVE-2025-39889MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on inco...
CVE-2025-58457MEDIUM4.3Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insu...
CVE-2025-9031MEDIUM4.3Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Doma...
CVE-2025-41716MEDIUM5.3The web application allows an unauthenticated remote attacker to learn information about existing user accounts with the...
CVE-2025-48459MEDIUM5.3Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0...
CVE-2025-43819MEDIUM6.5A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024....
CVE-2025-43779MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024...
CVE-2025-58069MEDIUM6.9The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerabili...
CVE-2025-54855MEDIUM4.2Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability...
CVE-2025-58354MEDIUM6.9Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2025-56311MEDIUM6.5In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authentic...
CVE-2025-59825MEDIUM6.1astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-...
CVE-2025-57636MEDIUM6.5OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injecti...
CVE-2025-58674MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows S...
CVE-2025-56146MEDIUM5.3Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.
CVE-2025-45326MEDIUM6.5An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.p...
CVE-2025-59821MEDIUM6.1DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-59548MEDIUM6.1DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-59547MEDIUM5.3DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-59546MEDIUM4.8DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-59539MEDIUM5.4DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-58246MEDIUM4.3Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. Th...
CVE-2025-57639MEDIUM6.5OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the ...
CVE-2025-29084MEDIUM6.5SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now