2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-43703MEDIUM5.4An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access ...
CVE-2025-32791MEDIUM4.3The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in t...
CVE-2025-32783MEDIUM4.3XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Str...
CVE-2025-3730MEDIUM5.5A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.func...
CVE-2025-29710MEDIUM6.1SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.
CVE-2025-26153MEDIUM5.4A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious ...
CVE-2025-32817MEDIUM6.1A Improper Link Resolution vulnerability (CWE-59) in the SonicWall Connect Tunnel Windows (32 and 64 bit) client, this r...
CVE-2025-22872MEDIUM6.5The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-c...
CVE-2025-3739MEDIUM5.9Vulnerability in Drupal Drupal 8 Google Optimize Hide Page.This issue affects Drupal 8 Google Optimize Hide Page: *.*.
CVE-2025-3738MEDIUM5.9Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.
CVE-2025-3737MEDIUM5.9Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.
CVE-2025-3736MEDIUM5.9Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.
CVE-2025-3735MEDIUM5.9Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.
CVE-2025-3734MEDIUM5.9Allocation of Resources Without Limits or Throttling vulnerability in Drupal Stage File Proxy allows Flooding.This issue...
CVE-2025-3733MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox...
CVE-2025-2564MEDIUM4.3Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to vi...
CVE-2025-20150MEDIUM5.3A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts...
CVE-2025-23138MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: watch_queue: fix pipe accounting mismatch Currentl...
CVE-2025-23137MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Add missing NULL ptr check in a...
CVE-2025-23136MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all ...
CVE-2025-23135MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Teardown riscv specific bits after kvm...
CVE-2025-23134MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Don't take register_mutex with copy_fr...
CVE-2025-23132MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: quota: fix to avoid warning in dquot_writebac...
CVE-2025-23131MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dlm: prevent NPD when writing a positive value to e...
CVE-2025-23130MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid panic once fallocation fails for...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now