2025 CVE Vulnerabilities

45,213 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22465MEDIUM6.1Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthentica...
CVE-2025-22464MEDIUM6.1An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022...
CVE-2025-22459MEDIUM4.8Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a r...
CVE-2025-30150MEDIUM5.3Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a at...
CVE-2025-22855MEDIUM4.8An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortin...
CVE-2025-2568MEDIUM5.3The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access...
CVE-2025-30166MEDIUM4.8Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. An HTML injection issue allows users with access to th...
CVE-2025-29985MEDIUM6.5Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Initialization of a Resource with an Insecure Default v...
CVE-2025-3437MEDIUM4.3The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification...
CVE-2025-2883MEDIUM5.3The Accept SagePay Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in...
CVE-2025-2808MEDIUM5.4The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2025-3436MEDIUM6.5The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'order' and...
CVE-2025-3433MEDIUM6.1The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including...
CVE-2025-3432MEDIUM6.4The AAWP Obfuscator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-aawp-web' parameter ...
CVE-2025-30280MEDIUM6.9A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions...
CVE-2025-30000MEDIUM6.7A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does...
CVE-2025-29999MEDIUM6.7A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application sear...
CVE-2025-22017MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: devlink: fix xa_alloc_cyclic() error handling In c...
CVE-2025-22016MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dpll: fix xa_alloc_cyclic() error handling In case...
CVE-2025-22015MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/migrate: fix shmem xarray update during migratio...
CVE-2025-22014MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: Fix the potential deadlock When so...
CVE-2025-22013MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unconditionally save+flush host FPSIMD/...
CVE-2025-22012MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: dts: qcom: sdm845: Affirm IDR0.CCTW ...
CVE-2025-22011MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ARM: dts: bcm2711: Fix xHCI power-domain During s2...
CVE-2025-22010MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix soft lockup during bt pages loop Dri...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now