2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-31334MEDIUM6.8Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points t...
CVE-2025-2055MEDIUM6.8The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in...
CVE-2025-3136MEDIUM4.8A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function t...
CVE-2025-2784MEDIUM6.5A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_ins...
CVE-2025-3153MEDIUM6.5Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Addre...
CVE-2025-3130MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate a...
CVE-2025-3129MEDIUM4.8Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This is...
CVE-2025-3122MEDIUM5.3A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the fu...
CVE-2025-3121MEDIUM5.5A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module...
CVE-2025-30218MEDIUM5.9Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the...
CVE-2025-29719MEDIUM6.1SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via...
CVE-2025-20203MEDIUM4.8A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri...
CVE-2025-20120MEDIUM6.1A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri...
CVE-2025-31728MEDIUM5.5Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configura...
CVE-2025-31727MEDIUM5.5Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files o...
CVE-2025-31726MEDIUM5.5Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Je...
CVE-2025-31725MEDIUM5.5Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller whe...
CVE-2025-31724MEDIUM4.3Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in j...
CVE-2025-31723MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier allows attackers to c...
CVE-2025-31721MEDIUM4.3A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create p...
CVE-2025-31720MEDIUM4.3A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create p...
CVE-2025-21994MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix incorrect validation for num_aces field ...
CVE-2025-21992MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: HID: ignore non-functional sensor in HP 5MP Camera ...
CVE-2025-21990MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: NULL-check BO's backing store when dete...
CVE-2025-21989MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix missing .is_two_pixels_per_con...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now