2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39794 | MEDIUM | 5.5 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ARM: tegra: Use I/O memcpy to write to IRAM Kasan ... |
| CVE-2025-39792 | MEDIUM | 5.5 | 0.1% | Sep 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: dm: Always split write BIOs to zoned device limits ... |
| CVE-2025-55996 | MEDIUM | 6.3 | 0.2% | Sep 12, 2025 | Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface |
| CVE-2025-10319 | MEDIUM | 6.5 | 0.3% | Sep 12, 2025 | A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of th... |
| CVE-2025-59139 | MEDIUM | 5.3 | 0.4% | Sep 12, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw... |
| CVE-2025-59058 | MEDIUM | 5.9 | 0.3% | Sep 12, 2025 | httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signatur... |
| CVE-2025-27233 | MEDIUM | 5.7 | 0.2% | Sep 12, 2025 | Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex... |
| CVE-2025-10267 | MEDIUM | 6.9 | 0.4% | Sep 12, 2025 | NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote at... |
| CVE-2025-8280 | MEDIUM | 5.8 | 0.2% | Sep 12, 2025 | The Contact Form 7 reCAPTCHA WordPress plugin through 1.2.0 does not escape the $_SERVER['REQUEST_URI'] parameter before... |
| CVE-2025-7337 | MEDIUM | 6.5 | 0.4% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3... |
| CVE-2025-6769 | MEDIUM | 4.3 | 0.3% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.... |
| CVE-2025-58781 | MEDIUM | 6.3 | 0.1% | Sep 12, 2025 | WTW-EAGLE App does not properly validate server certificates, which may allow a man-in-the-middle attacker to monitor en... |
| CVE-2025-1250 | MEDIUM | 6.5 | 0.4% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.... |
| CVE-2025-10148 | MEDIUM | 5.3 | 0.5% | Sep 12, 2025 | curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Inst... |
| CVE-2025-10288 | MEDIUM | 5.5 | 0.5% | Sep 12, 2025 | A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is a... |
| CVE-2025-10094 | MEDIUM | 6.5 | 0.4% | Sep 12, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.... |
| CVE-2025-9881 | MEDIUM | 6.1 | 0.1% | Sep 12, 2025 | The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2025-9880 | MEDIUM | 6.1 | 0.1% | Sep 12, 2025 | The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2025-9879 | MEDIUM | 6.4 | 0.2% | Sep 12, 2025 | The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' s... |
| CVE-2025-9877 | MEDIUM | 6.4 | 0.2% | Sep 12, 2025 | The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' sh... |
| CVE-2025-43789 | MEDIUM | 5.3 | 0.2% | Sep 12, 2025 | JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through... |
| CVE-2025-43788 | MEDIUM | 4.3 | 0.2% | Sep 12, 2025 | The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.... |
| CVE-2025-10274 | MEDIUM | 6.1 | 0.3% | Sep 12, 2025 | A security flaw has been discovered in erjinzhi 10OA 1.0. Affected by this issue is some unknown functionality of the fi... |
| CVE-2025-10273 | MEDIUM | 5.3 | 0.7% | Sep 12, 2025 | A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the f... |
| CVE-2025-10272 | MEDIUM | 6.1 | 0.3% | Sep 11, 2025 | A vulnerability was determined in erjinzhi 10OA 1.0. Affected is an unknown function of the file /trial/mvc/catalogue. T... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now