2025 CVE Vulnerabilities

45,331 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-29083MEDIUM6.5SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile fu...
CVE-2025-0209MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due...
CVE-2025-56304MEDIUM6.1Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.
CVE-2025-0663MEDIUM6.8A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Ada...
CVE-2025-57407MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticat...
CVE-2025-4760MEDIUM4.8An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper valida...
CVE-2025-9342MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privile...
CVE-2025-7106MEDIUM5.3danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `c...
CVE-2025-10548MEDIUM6.5The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the insta...
CVE-2025-39887MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix null-ptr-deref in bitmap_parse...
CVE-2025-39886MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Tell memcg to use allow_spinning=false path in...
CVE-2025-39885MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix recursive semaphore deadlock in fiemap c...
CVE-2025-39884MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: btrfs: fix subvolume deletion lockup caused by inod...
CVE-2025-39879MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ceph: always call ceph_shift_unused_folios_left() ...
CVE-2025-39878MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash after fscrypt_encrypt_pagecache_blo...
CVE-2025-39876MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: fec: Fix possible NPD in fec_enet_phy_reset_af...
CVE-2025-39875MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: igb: Fix NULL pointer dereference in ethtool loopba...
CVE-2025-39874MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: macsec: sync features on RTM_NEWLINK Syzkaller man...
CVE-2025-39872MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hsr: hold rcu and dev lock for hsr_get_port_ndev h...
CVE-2025-8902MEDIUM6.4The Widget Options - Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'do_sid...
CVE-2025-10837MEDIUM5.4A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerabil...
CVE-2025-58915MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design Req...
CVE-2025-42907MEDIUM4.3SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified...
CVE-2025-10827MEDIUM6.1A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown fun...
CVE-2025-10824MEDIUM5.3A vulnerability was determined in axboe fio up to 3.41. This impacts the function __parse_jobs_ini of the file init.c. E...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now