2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8103 | MEDIUM | 4.3 | 0.2% | Jul 26, 2025 | The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2025-54414 | MEDIUM | 5.1 | 0.5% | Jul 26, 2025 | Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to ... |
| CVE-2025-54380 | MEDIUM | 6.5 | 0.4% | Jul 26, 2025 | Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to vers... |
| CVE-2025-8174 | MEDIUM | 6.3 | 0.3% | Jul 26, 2025 | A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some ... |
| CVE-2025-8171 | MEDIUM | 6.3 | 0.3% | Jul 25, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This ... |
| CVE-2025-8167 | MEDIUM | 5.4 | 0.3% | Jul 25, 2025 | A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by ... |
| CVE-2025-52455 | MEDIUM | 5.3 | 0.3% | Jul 25, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) all... |
| CVE-2025-5449 | MEDIUM | 6.5 | 0.8% | Jul 25, 2025 | A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length... |
| CVE-2025-54596 | MEDIUM | 4.3 | 0.2% | Jul 25, 2025 | Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the privileges of other user accou... |
| CVE-2025-45960 | MEDIUM | 6.1 | 0.4% | Jul 25, 2025 | Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via t... |
| CVE-2025-45893 | MEDIUM | 6.1 | 0.2% | Jul 25, 2025 | OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog p... |
| CVE-2025-45892 | MEDIUM | 6.1 | 0.2% | Jul 25, 2025 | OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerabil... |
| CVE-2025-45406 | MEDIUM | 6.1 | 0.3% | Jul 25, 2025 | A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scrip... |
| CVE-2025-3873 | MEDIUM | 6 | 0.3% | Jul 25, 2025 | The following APIs for the Silcon Labs SiWx91x prior to vesion 3.4.0 failed to check the size of the output buffer of th... |
| CVE-2025-3508 | MEDIUM | 6.5 | 0.9% | Jul 25, 2025 | Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauth... |
| CVE-2025-38467 | MEDIUM | 5.5 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/exynos: exynos7_drm_decon: add vblank check in ... |
| CVE-2025-38466 | MEDIUM | 5.5 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: perf: Revert to requiring CAP_SYS_ADMIN for uprobes... |
| CVE-2025-38465 | MEDIUM | 5.5 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: netlink: Fix wraparounds of sk->sk_rmem_alloc. Net... |
| CVE-2025-38463 | MEDIUM | 5.5 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: tcp: Correct signedness in skb remaining space calc... |
| CVE-2025-38462 | MEDIUM | 4.7 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g} TOCTOU vsock_find_c... |
| CVE-2025-38461 | MEDIUM | 4.7 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment... |
| CVE-2025-38460 | MEDIUM | 5.5 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix potential null-ptr-deref in to_atmar... |
| CVE-2025-38458 | MEDIUM | 5.5 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix NULL pointer dereference in vcc_send... |
| CVE-2025-38457 | MEDIUM | 5.5 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/sched: Abort __tc_modify_qdisc if parent class ... |
| CVE-2025-38455 | MEDIUM | 5.5 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Reject SEV{-ES} intra host migration if v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now