2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-32063MEDIUM6.8There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens d...
CVE-2025-32060MEDIUM6.7The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on be...
CVE-2025-71223MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in smb2_open() When ...
CVE-2025-71222MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: ensure skb headroom before skb_push ...
CVE-2025-71204MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in parse_durable_hand...
CVE-2025-71202MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iommu/sva: invalidate stale IOTLB entries for kerne...
CVE-2025-71200MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci-of-dwcmshc: Prevent illegal clock reduct...
CVE-2025-6792MEDIUM5.3The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-15483MEDIUM4.4The Link Hopper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hop_name’ parameter in all ve...
CVE-2025-14873MEDIUM4.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Req...
CVE-2025-14852MEDIUM4.3The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2025-14608MEDIUM5.3The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ...
CVE-2025-14067MEDIUM5.3The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec...
CVE-2025-13973MEDIUM5.3The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versi...
CVE-2025-13681MEDIUM4.9The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and includi...
CVE-2025-66676MEDIUM6.2An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-1790MEDIUM5.8Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vu...
CVE-2025-70095MEDIUM6.5A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 all...
CVE-2025-70094MEDIUM6.5A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attacker...
CVE-2025-70091MEDIUM6.5A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute...
CVE-2025-48023MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-48022MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-48021MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...
CVE-2025-15520MEDIUM4.3The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure o...
CVE-2025-48020MEDIUM6.5A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now