2025 CVE Vulnerabilities

45,168 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-39742MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA: hfi1: fix possible divide-by-zero in find_hw_...
CVE-2025-39741MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: don't overflow max copy size With ...
CVE-2025-39739MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-qcom: Add SM6115 MDSS compatible Ad...
CVE-2025-39737MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup in __kmemleak_do_cle...
CVE-2025-39736MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid deadlock by moving pr_warn() out...
CVE-2025-26499MEDIUM6Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This ...
CVE-2025-8716MEDIUM5.8In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to dow...
CVE-2025-40696MEDIUM5.4Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ...
CVE-2025-40695MEDIUM5.4Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ...
CVE-2025-40694MEDIUM5.4Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ...
CVE-2025-40693MEDIUM5.4Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored ...
CVE-2025-10250MEDIUM5A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function ...
CVE-2025-48040MEDIUM6.9Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Floodi...
CVE-2025-48039MEDIUM5.3Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive...
CVE-2025-48038MEDIUM5.3Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive...
CVE-2025-9861MEDIUM6.4The ThemeLoom Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'los_showposts'...
CVE-2025-9860MEDIUM6.4The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mixtape' shortcode in al...
CVE-2025-9855MEDIUM6.4The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_aut...
CVE-2025-9850MEDIUM6.4The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'evenium_single_event' sh...
CVE-2025-9635MEDIUM4.3The Analytics Reduce Bounce Rate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,...
CVE-2025-9634MEDIUM4.3The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-9633MEDIUM4.3The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2....
CVE-2025-9632MEDIUM4.3The PhpList Subber plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2025-9631MEDIUM4.3The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2....
CVE-2025-9628MEDIUM4.3The The integration of the AMO.CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now