2025 CVE Vulnerabilities

45,342 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-39794MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ARM: tegra: Use I/O memcpy to write to IRAM Kasan ...
CVE-2025-39792MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dm: Always split write BIOs to zoned device limits ...
CVE-2025-55996MEDIUM6.3Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface
CVE-2025-10319MEDIUM6.5A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of th...
CVE-2025-59139MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw...
CVE-2025-59058MEDIUM5.9httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signatur...
CVE-2025-27233MEDIUM5.7Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex...
CVE-2025-10267MEDIUM6.9NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote at...
CVE-2025-8280MEDIUM5.8The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before...
CVE-2025-7337MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3...
CVE-2025-6769MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-58781MEDIUM6.3WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor en...
CVE-2025-1250MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-10148MEDIUM5.3curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Inst...
CVE-2025-10288MEDIUM5.5A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is a...
CVE-2025-10094MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18....
CVE-2025-9881MEDIUM6.1The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2025-9880MEDIUM6.1The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2025-9879MEDIUM6.4The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' s...
CVE-2025-9877MEDIUM6.4The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' sh...
CVE-2025-43789MEDIUM5.3JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through...
CVE-2025-43788MEDIUM4.3The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7....
CVE-2025-10274MEDIUM6.1A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the fi...
CVE-2025-10273MEDIUM5.3A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the f...
CVE-2025-10272MEDIUM6.1A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. T...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now