2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-70458MEDIUM5.4A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sou...
CVE-2025-52023MEDIUM5.3A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to t...
CVE-2025-52022MEDIUM5.3A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers ...
CVE-2025-14947MEDIUM6.5The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-71177MEDIUM5.4LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package crea...
CVE-2025-67231MEDIUM5.9A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary ...
CVE-2025-71161MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correcti...
CVE-2025-71160MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: avoid chain re-validation if ...
CVE-2025-71158MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IR...
CVE-2025-67125MEDIUM4.4A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern::match in docopt_private.h) when merging occurrence counters...
CVE-2025-67124MEDIUM6.8A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an atta...
CVE-2025-71154MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix memory leak on usb_submit_ur...
CVE-2025-71153MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix memory leak in get_file_all_info() In g...
CVE-2025-71151MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory and information leak in smb3_recon...
CVE-2025-71150MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix refcount leak when invalid session is fo...
CVE-2025-71147MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd ...
CVE-2025-71146MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error pat...
CVE-2025-13921MEDIUM4.3The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to unau...
CVE-2025-2204MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tapandsign ...
CVE-2025-46699MEDIUM6.5Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a...
CVE-2025-14745MEDIUM6.4The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to Stored...
CVE-2025-14069MEDIUM6.4The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sas...
CVE-2025-15522MEDIUM6.4The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera...
CVE-2025-9290MEDIUM5.9An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption d...
CVE-2025-67652MEDIUM6.1An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now