2025 CVE Vulnerabilities
45,168 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39742 | MEDIUM | 5.5 | 0.2% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: RDMA: hfi1: fix possible divide-by-zero in find_hw_... |
| CVE-2025-39741 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: don't overflow max copy size With ... |
| CVE-2025-39739 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-qcom: Add SM6115 MDSS compatible Ad... |
| CVE-2025-39737 | MEDIUM | 5.5 | 0.2% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup in __kmemleak_do_cle... |
| CVE-2025-39736 | MEDIUM | 5.5 | 0.1% | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid deadlock by moving pr_warn() out... |
| CVE-2025-26499 | MEDIUM | 6 | 0.1% | Sep 11, 2025 | Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This ... |
| CVE-2025-8716 | MEDIUM | 5.8 | 0.2% | Sep 11, 2025 | In Content Management versions 20.4- 25.3 authenticated attackers may exploit a complex cache poisoning technique to dow... |
| CVE-2025-40696 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ... |
| CVE-2025-40695 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ... |
| CVE-2025-40694 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ... |
| CVE-2025-40693 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored ... |
| CVE-2025-10250 | MEDIUM | 5 | 0.2% | Sep 11, 2025 | A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function ... |
| CVE-2025-48040 | MEDIUM | 6.9 | 0.4% | Sep 11, 2025 | Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Floodi... |
| CVE-2025-48039 | MEDIUM | 5.3 | 0.4% | Sep 11, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive... |
| CVE-2025-48038 | MEDIUM | 5.3 | 0.4% | Sep 11, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive... |
| CVE-2025-9861 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The ThemeLoom Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'los_showposts'... |
| CVE-2025-9860 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mixtape' shortcode in al... |
| CVE-2025-9855 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_aut... |
| CVE-2025-9850 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'evenium_single_event' sh... |
| CVE-2025-9635 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Analytics Reduce Bounce Rate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-9634 | MEDIUM | 4.3 | 0.1% | Sep 11, 2025 | The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-9633 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2025-9632 | MEDIUM | 4.3 | 0.1% | Sep 11, 2025 | The PhpList Subber plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-9631 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2025-9628 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The The integration of the AMO.CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now