2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38105 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Kill timer properly at removal Th... |
| CVE-2025-38100 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/iopl: Cure TIF_IO_BITMAP inconsistencies io_bi... |
| CVE-2025-38099 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Disable SCO support if READ_VOICE_SETTIN... |
| CVE-2025-38098 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Don't treat wb connector as physic... |
| CVE-2025-38097 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: espintcp: remove encap socket caching to avoid refe... |
| CVE-2025-38096 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: don't warn when if there is a FW err... |
| CVE-2025-38095 | MEDIUM | 5.5 | 0.2% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_... |
| CVE-2025-38094 | MEDIUM | 5.5 | 0.1% | Jul 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: cadence: macb: Fix a possible deadlock in macb... |
| CVE-2025-5944 | MEDIUM | 5.4 | 0.3% | Jul 3, 2025 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-ca... |
| CVE-2025-52842 | MEDIUM | 6.1 | 0.2% | Jul 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Laundry on ... |
| CVE-2025-52559 | MEDIUM | 5.4 | 0.2% | Jul 2, 2025 | Zulip is an open-source team chat application. From versions 2.0.0-rc1 to before 10.4 in Zulip Server, the /digest/ URL ... |
| CVE-2025-45424 | MEDIUM | 5.3 | 0.3% | Jul 2, 2025 | Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication. |
| CVE-2025-20307 | MEDIUM | 4.8 | 0.2% | Jul 2, 2025 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an ... |
| CVE-2025-6943 | MEDIUM | 4 | 0.1% | Jul 2, 2025 | Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator... |
| CVE-2025-53359 | MEDIUM | 6.9 | 0.4% | Jul 2, 2025 | ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EI... |
| CVE-2025-53358 | MEDIUM | 6.5 | 0.4% | Jul 2, 2025 | kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/... |
| CVE-2025-52886 | MEDIUM | 5.9 | 0.4% | Jul 2, 2025 | Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std... |
| CVE-2025-20310 | MEDIUM | 6.1 | 0.2% | Jul 2, 2025 | A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker t... |
| CVE-2025-20308 | MEDIUM | 6.7 | 0.2% | Jul 2, 2025 | A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute... |
| CVE-2025-6725 | MEDIUM | 5.4 | 0.2% | Jul 2, 2025 | In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has a... |
| CVE-2025-53494 | MEDIUM | 6.5 | 0.2% | Jul 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53493 | MEDIUM | 6.5 | 0.2% | Jul 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53108 | MEDIUM | 5.3 | 0.3% | Jul 2, 2025 | HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in ... |
| CVE-2025-52891 | MEDIUM | 6.5 | 0.3% | Jul 2, 2025 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versio... |
| CVE-2025-38093 | MEDIUM | 5.5 | 0.1% | Jul 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: x1e80100: Add GPU cooling Unlike... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now