2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7078MEDIUM4.3A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability ...
CVE-2025-47228MEDIUM6.7In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connecti...
CVE-2025-53605MEDIUM5.9The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputSt...
CVE-2025-53604MEDIUM4The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the built-in clients via a ...
CVE-2025-7069MEDIUM5.5A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link...
CVE-2025-7068MEDIUM5.5A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5F...
CVE-2025-53602MEDIUM5.3Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-...
CVE-2025-7067MEDIUM5.5A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_...
CVE-2025-53482MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-52497MEDIUM4.8Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls...
CVE-2025-49601MEDIUM6.5In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes be...
CVE-2025-49600MEDIUM4.9In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal e...
CVE-2025-38234MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======...
CVE-2025-38232MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and export...
CVE-2025-38231MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfsd: Initialize ssc before laundromat_work to prev...
CVE-2025-38229MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: cxusb: no longer judge rbuf when the write f...
CVE-2025-38228MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: imagination: fix a potential memory leak in ...
CVE-2025-38225MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Cleanup after an allocation error ...
CVE-2025-38223MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ceph: avoid kernel BUG for encrypted inode with una...
CVE-2025-38222MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: inline: fix len overflow in ext4_prepare_inli...
CVE-2025-38220MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: only dirty folios when data journaling regula...
CVE-2025-38219MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: prevent kernel warning due to negative i_nlin...
CVE-2025-38218MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on sit_bitmap_size w/...
CVE-2025-38217MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: hwmon: (ftsteutates) Fix TOCTOU race in fts_read() ...
CVE-2025-38215MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix do_register_framebuffer to prevent null-...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now