2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-23148MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: soc: samsung: exynos-chipid: Add NULL pointer check...
CVE-2025-23147MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i3c: Add NULL pointer check in i3c_master_queue_ibi...
CVE-2025-23146MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mfd: ene-kb3930: Fix a potential NULL pointer deref...
CVE-2025-23145MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mptcp: fix NULL pointer in can_accept_new_subflow ...
CVE-2025-23144MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when callin...
CVE-2025-23143MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and...
CVE-2025-23141MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to prote...
CVE-2025-23140MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Avoid issue of interrupts ...
CVE-2025-3890MEDIUM5.4The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w...
CVE-2025-3889MEDIUM5.3The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version...
CVE-2025-3874MEDIUM6.5The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version...
CVE-2025-1529MEDIUM6.4The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded lottie files in all v...
CVE-2025-4100MEDIUM6.4The Nautic Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'np_marinetraffic_ma...
CVE-2025-47153MEDIUM6.5Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_2...
CVE-2025-3521MEDIUM6.4The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vul...
CVE-2025-3504MEDIUM4.8The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high...
CVE-2025-3503MEDIUM4.8The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high...
CVE-2025-3502MEDIUM4.8The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high...
CVE-2025-4099MEDIUM5.4The List Children plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list_children' sho...
CVE-2025-2168MEDIUM4.3The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc...
CVE-2025-4143MEDIUM6.1The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-...
CVE-2025-30422MEDIUM6.5A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPl...
CVE-2025-24132MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video ...
CVE-2025-4136MEDIUM5.4A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the...
CVE-2025-46554MEDIUM5.3XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now