2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31120 | MEDIUM | 5.3 | 0.4% | Apr 18, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an inse... |
| CVE-2025-30357 | MEDIUM | 6.8 | 0.4% | Apr 18, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a ma... |
| CVE-2025-27599 | MEDIUM | 6.5 | 0.3% | Apr 18, 2025 | Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a ... |
| CVE-2025-3791 | MEDIUM | 5.3 | 0.2% | Apr 18, 2025 | A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This ... |
| CVE-2025-2950 | MEDIUM | 5.4 | 0.2% | Apr 18, 2025 | IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP h... |
| CVE-2025-3790 | MEDIUM | 6.9 | 0.6% | Apr 18, 2025 | A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /dr... |
| CVE-2025-3789 | MEDIUM | 5.4 | 0.3% | Apr 18, 2025 | A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown... |
| CVE-2025-32790 | MEDIUM | 4.3 | 0.2% | Apr 18, 2025 | Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the ... |
| CVE-2025-3788 | MEDIUM | 5.4 | 0.3% | Apr 18, 2025 | A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is a... |
| CVE-2025-3787 | MEDIUM | 6.5 | 0.4% | Apr 18, 2025 | A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of t... |
| CVE-2025-3106 | MEDIUM | 6.4 | 0.3% | Apr 18, 2025 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2025-3056 | MEDIUM | 5.4 | 0.3% | Apr 18, 2025 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi... |
| CVE-2025-40325 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard re... |
| CVE-2025-39989 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-... |
| CVE-2025-39930 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Don't use __free(device_no... |
| CVE-2025-39755 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_... |
| CVE-2025-39728 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init()... |
| CVE-2025-39688 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via n... |
| CVE-2025-38637 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue asse... |
| CVE-2025-38575 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_... |
| CVE-2025-38240 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to... |
| CVE-2025-38152 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdow... |
| CVE-2025-38104 | MEDIUM | 4.7 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Replace Mutex with Spinlock for RLCG re... |
| CVE-2025-38049 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/resctrl: Fix allocation of cleanest CLOSID on p... |
| CVE-2025-37925 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now