2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-38356MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Explicitly exit CT safe mode on unwind ...
CVE-2025-38355MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe: Process deferred GGTT node removals on devi...
CVE-2025-38354MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/msm/gpu: Fix crash when throttling GPU immediat...
CVE-2025-38353MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix taking invalid lock on wedge If device...
CVE-2025-8155MEDIUM5.4A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this vulnerability...
CVE-2025-5254MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Techno...
CVE-2025-5253MEDIUM6.5Allocation of Resources Without Limits or Throttling vulnerability in Kron Technologies Kron PAM allows HTTP DoS. This ...
CVE-2025-8133MEDIUM6.3A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This affects the function get...
CVE-2025-7022MEDIUM6.1The My Reservation System WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it bac...
CVE-2025-8132MEDIUM5.4A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is ...
CVE-2025-8129MEDIUM6.1A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back ...
CVE-2025-8128MEDIUM6.3A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de4...
CVE-2025-54567MEDIUM5.4hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
CVE-2025-54566MEDIUM5.4hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
CVE-2025-54558MEDIUM4.1OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search...
CVE-2025-0252MEDIUM4.8HCL IEM is affected by a password in cleartext vulnerability.  Sensitive information is transmitted without adequate pro...
CVE-2025-0251MEDIUM5.7HCL IEM is affected by a concurrent login vulnerability.  The application allows multiple concurrent sessions using the ...
CVE-2025-0250MEDIUM4.9HCL IEM is affected by an authorization token sent in cookie vulnerability.  A token used for authentication and authori...
CVE-2025-0249MEDIUM5.9HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which...
CVE-2025-3614MEDIUM5.4The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-31955MEDIUM6.5HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensi...
CVE-2025-31953MEDIUM6.5HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted ...
CVE-2025-8115MEDIUM5.4A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by...
CVE-2025-45702MEDIUM6.5SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext.
CVE-2025-53084MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now