2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-37893MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prolo...
CVE-2025-37860MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_...
CVE-2025-3598MEDIUM6.1The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri...
CVE-2025-2162MEDIUM4.8The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could all...
CVE-2025-2613MEDIUM4.4The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to S...
CVE-2025-25427MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/...
CVE-2025-3124MEDIUM4.3A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of...
CVE-2025-29456MEDIUM6.5An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in...
CVE-2025-29453MEDIUM6.5An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in...
CVE-2025-29455MEDIUM6.5An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in...
CVE-2025-29454MEDIUM6.5An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in...
CVE-2025-29450MEDIUM6.5An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings comp...
CVE-2025-29449MEDIUM6.5An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identificatio...
CVE-2025-29316MEDIUM6.2An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker t...
CVE-2025-29722MEDIUM6.3A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticat...
CVE-2025-28101MEDIUM6.5An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to dele...
CVE-2025-26269MEDIUM5.5DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon c...
CVE-2025-26268MEDIUM6.5DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted...
CVE-2025-43015MEDIUM6.5In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
CVE-2025-43014MEDIUM6.5In JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmation
CVE-2025-42921MEDIUM6.5In JetBrains Toolbox App before 2.6 host key verification was missing in SSH plugin
CVE-2025-39580MEDIUM5.8Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by ...
CVE-2025-39562MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Payment...
CVE-2025-39559MEDIUM6.5Missing Authorization vulnerability in Eivin Landa Bring Fraktguiden for WooCommerce bring-fraktguiden-for-woocommerce a...
CVE-2025-39554MEDIUM6.5Missing Authorization vulnerability in Elliot Sowersby / RelyWP AI Text to Speech ai-text-to-speech allows Exploiting In...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now