2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-38105MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Kill timer properly at removal Th...
CVE-2025-38100MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/iopl: Cure TIF_IO_BITMAP inconsistencies io_bi...
CVE-2025-38099MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Disable SCO support if READ_VOICE_SETTIN...
CVE-2025-38098MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Don't treat wb connector as physic...
CVE-2025-38097MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: espintcp: remove encap socket caching to avoid refe...
CVE-2025-38096MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: don't warn when if there is a FW err...
CVE-2025-38095MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_...
CVE-2025-38094MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: cadence: macb: Fix a possible deadlock in macb...
CVE-2025-5944MEDIUM5.4The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-ca...
CVE-2025-52842MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Laundry on ...
CVE-2025-52559MEDIUM5.4Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL ...
CVE-2025-45424MEDIUM5.3Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.
CVE-2025-20307MEDIUM4.8A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an ...
CVE-2025-6943MEDIUM4Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator...
CVE-2025-53359MEDIUM6.9ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EI...
CVE-2025-53358MEDIUM6.5kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/...
CVE-2025-52886MEDIUM5.9Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std...
CVE-2025-20310MEDIUM6.1A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker t...
CVE-2025-20308MEDIUM6.7A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute...
CVE-2025-6725MEDIUM5.4In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has a...
CVE-2025-53494MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53493MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53108MEDIUM5.3HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in ...
CVE-2025-52891MEDIUM6.5ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versio...
CVE-2025-38093MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: x1e80100: Add GPU cooling Unlike...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now