2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-37806 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Keep write operations atomic syzbot repo... |
| CVE-2025-37805 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitial... |
| CVE-2025-37802 | MEDIUM | 5.5 | 0.1% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !... |
| CVE-2025-37801 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Ad... |
| CVE-2025-37800 | MEDIUM | 5.5 | 0.2% | May 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference... |
| CVE-2025-32873 | MEDIUM | 5.3 | 14.0% | May 8, 2025 | An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip... |
| CVE-2025-35939 | MEDIUM | 5.3 | 1.1% | May 7, 2025 | Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed an... |
| CVE-2025-32441 | MEDIUM | 4.2 | 0.2% | May 7, 2025 | Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, s... |
| CVE-2025-0936 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with ... |
| CVE-2025-46821 | MEDIUM | 5.3 | 0.2% | May 7, 2025 | Envoy is a cloud-native edge/middle/service proxy. Prior to versions 1.34.1, 1.33.3, 1.32.6, and 1.31.8, Envoy's URI tem... |
| CVE-2025-4043 | MEDIUM | 6.8 | 0.3% | May 7, 2025 | An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system ... |
| CVE-2025-31177 | MEDIUM | 5.5 | 0.2% | May 7, 2025 | gnuplot is affected by a heap buffer overflow at function utf8_copy_one. |
| CVE-2025-45514 | MEDIUM | 6.5 | 0.2% | May 7, 2025 | Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.frmL7ImForm. |
| CVE-2025-45388 | MEDIUM | 6.1 | 0.3% | May 7, 2025 | Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers c... |
| CVE-2025-3272 | MEDIUM | 6.7 | 0.2% | May 7, 2025 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allow authentica... |
| CVE-2025-29746 | MEDIUM | 6.1 | 0.2% | May 7, 2025 | Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the colle... |
| CVE-2025-47423 | MEDIUM | 5.8 | 2.1% | May 7, 2025 | Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ direct... |
| CVE-2025-47203 | MEDIUM | 4.5 | 0.6% | May 7, 2025 | dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is ... |
| CVE-2025-20223 | MEDIUM | 4.7 | 0.2% | May 7, 2025 | A vulnerability in Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to re... |
| CVE-2025-20216 | MEDIUM | 4.3 | 0.3% | May 7, 2025 | A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an una... |
| CVE-2025-20214 | MEDIUM | 4.3 | 0.3% | May 7, 2025 | A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authen... |
| CVE-2025-20213 | MEDIUM | 5.5 | 0.1% | May 7, 2025 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated... |
| CVE-2025-20201 | MEDIUM | 6.7 | 0.1% | May 7, 2025 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15... |
| CVE-2025-20196 | MEDIUM | 5.3 | 0.4% | May 7, 2025 | A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could a... |
| CVE-2025-20195 | MEDIUM | 4.3 | 0.2% | May 7, 2025 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote at... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now