2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-38629MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ALSA: usb: scarlett2: Fix missing NULL check scarl...
CVE-2025-38628MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix release of uninitialized resources o...
CVE-2025-38626MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to trigger foreground gc during f2fs_map_...
CVE-2025-38625MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vfio/pds: Fix missing detach_ioas op When CONFIG_I...
CVE-2025-38624MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Clean up allocated IRQs on unplug Wh...
CVE-2025-38623MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Fix surprise plug detection and recov...
CVE-2025-38622MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: drop UFO packets in udp_rcv_segment() When se...
CVE-2025-38621MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: md: make rdev_addable usable for rcu mode Our test...
CVE-2025-38619MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: fix list_del corruption I...
CVE-2025-36042MEDIUM5.4IBM QRadar SIEM 7.5 through 7.5.0 Dashboard is vulnerable to cross-site scripting. This vulnerability allows an authenti...
CVE-2025-51825MEDIUM6.5JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/...
CVE-2025-50691MEDIUM5.3MCSManager 10.5.3 daemon process runs as a root account by default, and its sensitive data (including tokens and termina...
CVE-2025-38617MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and pac...
CVE-2025-9331MEDIUM4.3The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2025-57896MEDIUM5.3Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc...
CVE-2025-57895MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This iss...
CVE-2025-57894MEDIUM4.3Missing Authorization vulnerability in ollybach WPPizza wppizza allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-57893MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Re...
CVE-2025-57892MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Jeff Starr Simple Statistics for Feeds simple-feed-stats allows Cross...
CVE-2025-57891MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Recurr...
CVE-2025-57890MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Sess...
CVE-2025-57888MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NooTheme Jobmonster noo-jobm...
CVE-2025-57887MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonste...
CVE-2025-57886MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Equalize Digital Accessibility Checker by Equalize Dig...
CVE-2025-57885MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Cross Site Reque...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now