2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23148 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: soc: samsung: exynos-chipid: Add NULL pointer check... |
| CVE-2025-23147 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: i3c: Add NULL pointer check in i3c_master_queue_ibi... |
| CVE-2025-23146 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: mfd: ene-kb3930: Fix a potential NULL pointer deref... |
| CVE-2025-23145 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix NULL pointer in can_accept_new_subflow ... |
| CVE-2025-23144 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when callin... |
| CVE-2025-23143 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and... |
| CVE-2025-23141 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to prote... |
| CVE-2025-23140 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Avoid issue of interrupts ... |
| CVE-2025-3890 | MEDIUM | 5.4 | 0.2% | May 1, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w... |
| CVE-2025-3889 | MEDIUM | 5.3 | 0.3% | May 1, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version... |
| CVE-2025-3874 | MEDIUM | 6.5 | 0.3% | May 1, 2025 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version... |
| CVE-2025-1529 | MEDIUM | 6.4 | 0.2% | May 1, 2025 | The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded lottie files in all v... |
| CVE-2025-4100 | MEDIUM | 6.4 | 0.2% | May 1, 2025 | The Nautic Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'np_marinetraffic_ma... |
| CVE-2025-47153 | MEDIUM | 6.5 | 0.3% | May 1, 2025 | Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_2... |
| CVE-2025-3521 | MEDIUM | 6.4 | 0.2% | May 1, 2025 | The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is vul... |
| CVE-2025-3504 | MEDIUM | 4.8 | 0.2% | May 1, 2025 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high... |
| CVE-2025-3503 | MEDIUM | 4.8 | 0.2% | May 1, 2025 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high... |
| CVE-2025-3502 | MEDIUM | 4.8 | 0.3% | May 1, 2025 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high... |
| CVE-2025-4099 | MEDIUM | 5.4 | 0.2% | May 1, 2025 | The List Children plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list_children' sho... |
| CVE-2025-2168 | MEDIUM | 4.3 | 0.2% | May 1, 2025 | The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc... |
| CVE-2025-4143 | MEDIUM | 6.1 | 0.3% | May 1, 2025 | The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-... |
| CVE-2025-30422 | MEDIUM | 6.5 | 0.6% | Apr 30, 2025 | A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPl... |
| CVE-2025-24132 | MEDIUM | 6.5 | 3.1% | Apr 30, 2025 | The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video ... |
| CVE-2025-4136 | MEDIUM | 5.4 | 0.3% | Apr 30, 2025 | A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the... |
| CVE-2025-46554 | MEDIUM | 5.3 | 0.9% | Apr 30, 2025 | XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now