2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38268 | MEDIUM | 5.5 | 0.1% | Jul 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: move tcpm_queue_vdm_unlocked to a... |
| CVE-2025-38266 | MEDIUM | 5.5 | 0.1% | Jul 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: eint: Fix invalid pointer derefe... |
| CVE-2025-38265 | MEDIUM | 5.5 | 0.2% | Jul 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: serial: jsm: fix NPE during jsm_uart_port_init No ... |
| CVE-2025-32989 | MEDIUM | 5.3 | 1.2% | Jul 10, 2025 | A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Cert... |
| CVE-2025-7387 | MEDIUM | 5.5 | 0.3% | Jul 10, 2025 | The Lana Downloads Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the endpoint parameters... |
| CVE-2025-6236 | MEDIUM | 4.8 | 0.2% | Jul 10, 2025 | The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2025-6234 | MEDIUM | 6.1 | 0.2% | Jul 10, 2025 | The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2025-46406 | MEDIUM | 5.6 | 0.1% | Jul 10, 2025 | A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high l... |
| CVE-2025-44003 | MEDIUM | 4.3 | 0.2% | Jul 10, 2025 | Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with ... |
| CVE-2025-35983 | MEDIUM | 6.5 | 0.2% | Jul 10, 2025 | Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged atta... |
| CVE-2025-5807 | MEDIUM | 6.1 | 0.2% | Jul 10, 2025 | The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ param... |
| CVE-2025-4406 | MEDIUM | 5.4 | 0.2% | Jul 10, 2025 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ... |
| CVE-2025-6976 | MEDIUM | 5.4 | 0.2% | Jul 9, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-6975 | MEDIUM | 6.1 | 0.3% | Jul 9, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S... |
| CVE-2025-0140 | MEDIUM | 6.8 | 0.1% | Jul 9, 2025 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ... |
| CVE-2025-0139 | MEDIUM | 6.3 | 0.1% | Jul 9, 2025 | An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a loc... |
| CVE-2025-52357 | MEDIUM | 4.1 | 0.3% | Jul 9, 2025 | Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firm... |
| CVE-2025-36599 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulne... |
| CVE-2025-44525 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient perm... |
| CVE-2025-7381 | MEDIUM | 5.3 | 0.2% | Jul 9, 2025 | ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the ... |
| CVE-2025-53743 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration f... |
| CVE-2025-53742 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the ... |
| CVE-2025-53678 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file... |
| CVE-2025-53677 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasi... |
| CVE-2025-53676 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now