2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-38354MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/msm/gpu: Fix crash when throttling GPU immediat...
CVE-2025-38353MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix taking invalid lock on wedge If device...
CVE-2025-8155MEDIUM5.4A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this vulnerability...
CVE-2025-5254MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Techno...
CVE-2025-5253MEDIUM6.5Allocation of Resources Without Limits or Throttling vulnerability in Kron Technologies Kron PAM allows HTTP DoS. This ...
CVE-2025-8133MEDIUM6.3A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This affects the function get...
CVE-2025-7022MEDIUM6.1The My Reservation System WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it bac...
CVE-2025-8132MEDIUM5.4A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is ...
CVE-2025-8129MEDIUM6.1A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back ...
CVE-2025-8128MEDIUM6.3A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de4...
CVE-2025-54567MEDIUM5.4hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.
CVE-2025-54566MEDIUM5.4hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.
CVE-2025-54558MEDIUM4.1OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search...
CVE-2025-0252MEDIUM4.8HCL IEM is affected by a password in cleartext vulnerability.  Sensitive information is transmitted without adequate pro...
CVE-2025-0251MEDIUM5.7HCL IEM is affected by a concurrent login vulnerability.  The application allows multiple concurrent sessions using the ...
CVE-2025-0250MEDIUM4.9HCL IEM is affected by an authorization token sent in cookie vulnerability.  A token used for authentication and authori...
CVE-2025-0249MEDIUM5.9HCL IEM is affected by an improper invalidation of access or JWT token vulnerability.  A token was not invalidated which...
CVE-2025-3614MEDIUM5.4The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-31955MEDIUM6.5HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensi...
CVE-2025-31953MEDIUM6.5HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted ...
CVE-2025-8115MEDIUM5.4A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by...
CVE-2025-45702MEDIUM6.5SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext.
CVE-2025-53084MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and...
CVE-2025-50128MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVide...
CVE-2025-47061MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now