2025 CVE Vulnerabilities

45,179 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-38268MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: move tcpm_queue_vdm_unlocked to a...
CVE-2025-38266MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: eint: Fix invalid pointer derefe...
CVE-2025-38265MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: serial: jsm: fix NPE during jsm_uart_port_init No ...
CVE-2025-32989MEDIUM5.3A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Cert...
CVE-2025-7387MEDIUM5.5The Lana Downloads Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the endpoint parameters...
CVE-2025-6236MEDIUM4.8The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2025-6234MEDIUM6.1The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2025-46406MEDIUM5.6A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high l...
CVE-2025-44003MEDIUM4.3Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with ...
CVE-2025-35983MEDIUM6.5Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged atta...
CVE-2025-5807MEDIUM6.1The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ param...
CVE-2025-4406MEDIUM5.4The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ...
CVE-2025-6976MEDIUM5.4The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-6975MEDIUM6.1The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2025-0140MEDIUM6.8An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ...
CVE-2025-0139MEDIUM6.3An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a loc...
CVE-2025-52357MEDIUM4.1Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firm...
CVE-2025-36599MEDIUM6.5Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulne...
CVE-2025-44525MEDIUM6.5Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient perm...
CVE-2025-7381MEDIUM5.3ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the ...
CVE-2025-53743MEDIUM5.3Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration f...
CVE-2025-53742MEDIUM6.5Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the ...
CVE-2025-53678MEDIUM6.5Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file...
CVE-2025-53677MEDIUM5.3Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasi...
CVE-2025-53676MEDIUM6.5Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now