2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-31091MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolut...
CVE-2025-30916MEDIUM6.5Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all...
CVE-2025-30915MEDIUM6.5Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition small-package-...
CVE-2025-30596MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tstafford include-file i...
CVE-2025-2946MEDIUM6.1pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrar...
CVE-2025-2299MEDIUM6.1The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2025-3152MEDIUM5.1A vulnerability classified as problematic has been found in caipeichao ThinkOX 1.0. This affects an unknown part of the ...
CVE-2025-3150MEDIUM5.3A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been declared as problematic....
CVE-2025-3149MEDIUM4.8A vulnerability was found in itning Student Homework Management System up to 1.2.7. It has been classified as problemati...
CVE-2025-2874MEDIUM4.4The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored ...
CVE-2025-22007MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix error code in chan_alloc_skb_cb() T...
CVE-2025-22006MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: Fix NAPI registration...
CVE-2025-22005MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix memleak of nhc_pcpu_rth_output in fib_che...
CVE-2025-22003MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix out of bound read in strscpy() sourc...
CVE-2025-22002MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfs: Call `invalidate_cache` only if implemented ...
CVE-2025-22001MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Fix integer overflow in qaic_validate_r...
CVE-2025-22000MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: drop beyond-EOF folios with the rig...
CVE-2025-21998MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registratio...
CVE-2025-21997MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xsk: fix an integer overflow in xp_create_and_assig...
CVE-2025-21996MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix uninitialized size issue in radeon_...
CVE-2025-21995MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix fence reference count leak The last...
CVE-2025-1663MEDIUM5.4The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widge...
CVE-2025-3145MEDIUM4.8A vulnerability, which was classified as problematic, has been found in MindSpore 2.5.0. Affected by this issue is the f...
CVE-2025-30485MEDIUM6.2UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attachin...
CVE-2025-3144MEDIUM4.8A vulnerability classified as problematic was found in MindSpore 2.5.0. Affected by this vulnerability is the function m...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now