2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-6866MEDIUM4.3A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects ...
CVE-2025-6865MEDIUM4.3A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of ...
CVE-2025-6864MEDIUM4.3A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is som...
CVE-2025-6858MEDIUM5.5A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flus...
CVE-2025-6854MEDIUM4.3A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability...
CVE-2025-6849MEDIUM4.1A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknow...
CVE-2025-6462MEDIUM5.4The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2025-6839MEDIUM6.3A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluat...
CVE-2025-53393MEDIUM6In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.
CVE-2025-53392MEDIUM6.5In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_comma...
CVE-2025-5937MEDIUM4.3The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable ...
CVE-2025-38086MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nw...
CVE-2025-38085MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race...
CVE-2025-38084MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, n...
CVE-2025-6252MEDIUM5.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ...
CVE-2025-6350MEDIUM5.4The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-...
CVE-2025-36027MEDIUM5.4IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By pe...
CVE-2025-36026MEDIUM4.3IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Atta...
CVE-2025-6778MEDIUM4.8A vulnerability, which was classified as problematic, was found in code-projects Food Distributor Site 1.0. Affected is ...
CVE-2025-6774MEDIUM6.3A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been rated as critical. Affected by this issue is th...
CVE-2025-6773MEDIUM5.3A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerabilit...
CVE-2025-6522MEDIUM5.4Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerabl...
CVE-2025-46708MEDIUM4.3Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from runn...
CVE-2025-46707MEDIUM5.2Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.
CVE-2025-44559MEDIUM6.5An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth ra...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now