2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31334 | MEDIUM | 6.8 | 1.2% | Apr 3, 2025 | Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points t... |
| CVE-2025-2055 | MEDIUM | 6.8 | 0.4% | Apr 3, 2025 | The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in... |
| CVE-2025-3136 | MEDIUM | 4.8 | 0.2% | Apr 3, 2025 | A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function t... |
| CVE-2025-2784 | MEDIUM | 6.5 | 0.7% | Apr 3, 2025 | A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_ins... |
| CVE-2025-3153 | MEDIUM | 6.5 | 0.2% | Apr 3, 2025 | Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Addre... |
| CVE-2025-3130 | MEDIUM | 5.4 | 0.2% | Apr 2, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate a... |
| CVE-2025-3129 | MEDIUM | 4.8 | 0.2% | Apr 2, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This is... |
| CVE-2025-3122 | MEDIUM | 5.3 | 0.5% | Apr 2, 2025 | A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the fu... |
| CVE-2025-3121 | MEDIUM | 5.5 | 0.2% | Apr 2, 2025 | A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module... |
| CVE-2025-30218 | MEDIUM | 5.9 | 0.4% | Apr 2, 2025 | Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the... |
| CVE-2025-29719 | MEDIUM | 6.1 | 0.3% | Apr 2, 2025 | SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via... |
| CVE-2025-20203 | MEDIUM | 4.8 | 0.3% | Apr 2, 2025 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2025-20120 | MEDIUM | 6.1 | 0.3% | Apr 2, 2025 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2025-31728 | MEDIUM | 5.5 | 0.3% | Apr 2, 2025 | Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configura... |
| CVE-2025-31727 | MEDIUM | 5.5 | 0.3% | Apr 2, 2025 | Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files o... |
| CVE-2025-31726 | MEDIUM | 5.5 | 0.3% | Apr 2, 2025 | Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Je... |
| CVE-2025-31725 | MEDIUM | 5.5 | 0.3% | Apr 2, 2025 | Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller whe... |
| CVE-2025-31724 | MEDIUM | 4.3 | 0.3% | Apr 2, 2025 | Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in j... |
| CVE-2025-31723 | MEDIUM | 4.3 | 0.2% | Apr 2, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier allows attackers to c... |
| CVE-2025-31721 | MEDIUM | 4.3 | 0.4% | Apr 2, 2025 | A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create p... |
| CVE-2025-31720 | MEDIUM | 4.3 | 0.4% | Apr 2, 2025 | A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create p... |
| CVE-2025-21994 | MEDIUM | 5.5 | 0.2% | Apr 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix incorrect validation for num_aces field ... |
| CVE-2025-21992 | MEDIUM | 5.5 | 0.2% | Apr 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: HID: ignore non-functional sensor in HP 5MP Camera ... |
| CVE-2025-21990 | MEDIUM | 5.5 | 0.2% | Apr 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: NULL-check BO's backing store when dete... |
| CVE-2025-21989 | MEDIUM | 5.5 | 0.2% | Apr 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix missing .is_two_pixels_per_con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now