2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21988 | MEDIUM | 5.5 | 0.2% | Apr 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated I... |
| CVE-2025-21987 | MEDIUM | 5.5 | 0.2% | Apr 2, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: init return value in amdgpu_ttm_clear_b... |
| CVE-2025-1805 | MEDIUM | 5.3 | 0.4% | Apr 2, 2025 | Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes. |
| CVE-2025-2842 | MEDIUM | 4.3 | 0.4% | Apr 2, 2025 | A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance mana... |
| CVE-2025-2786 | MEDIUM | 4.3 | 0.3% | Apr 2, 2025 | A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user d... |
| CVE-2025-3099 | MEDIUM | 6.1 | 0.2% | Apr 2, 2025 | The Advanced Search by My Solr Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2025-3098 | MEDIUM | 6.1 | 0.3% | Apr 2, 2025 | The Video Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all version... |
| CVE-2025-3097 | MEDIUM | 6.1 | 0.3% | Apr 2, 2025 | The wp Time Machine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-2513 | MEDIUM | 6.4 | 0.3% | Apr 2, 2025 | The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ... |
| CVE-2025-2483 | MEDIUM | 6.1 | 0.2% | Apr 2, 2025 | The Gift Certificate Creator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘receip_addres... |
| CVE-2025-27244 | MEDIUM | 5.9 | 0.4% | Apr 2, 2025 | AssetView and AssetView CLOUD contain an issue with acquiring sensitive information from sent data to the developer. If ... |
| CVE-2025-2779 | MEDIUM | 6.5 | 0.3% | Apr 2, 2025 | The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to unauthorized modification of data ... |
| CVE-2025-3074 | MEDIUM | 5.4 | 0.3% | Apr 2, 2025 | Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform U... |
| CVE-2025-3073 | MEDIUM | 5.4 | 0.3% | Apr 2, 2025 | Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced... |
| CVE-2025-3072 | MEDIUM | 5.4 | 0.3% | Apr 2, 2025 | Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convin... |
| CVE-2025-3071 | MEDIUM | 5.4 | 0.2% | Apr 2, 2025 | Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convin... |
| CVE-2025-3070 | MEDIUM | 6.5 | 0.3% | Apr 2, 2025 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attack... |
| CVE-2025-29982 | MEDIUM | 6.8 | 0.1% | Apr 2, 2025 | Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low p... |
| CVE-2025-27693 | MEDIUM | 4.8 | 0.2% | Apr 2, 2025 | Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Gene... |
| CVE-2025-31135 | MEDIUM | 5.3 | 0.3% | Apr 1, 2025 | Go-Guerrilla SMTP Daemon is a lightweight SMTP server written in Go. Prior to 1.6.7, when ProxyOn is enabled, the PROXY ... |
| CVE-2025-31889 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petesheppard84 Ext... |
| CVE-2025-31819 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Bl... |
| CVE-2025-31753 | MEDIUM | 4.3 | 0.2% | Apr 1, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser advanced-speed-increaser.This ... |
| CVE-2025-31628 | MEDIUM | 5.3 | 0.3% | Apr 1, 2025 | Missing Authorization vulnerability in SlicedInvoices Sliced Invoices sliced-invoices allows Exploiting Incorrectly Conf... |
| CVE-2025-31550 | MEDIUM | 5.8 | 0.4% | Apr 1, 2025 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in thom4 WP-LESS wp-less a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now