2025 CVE Vulnerabilities

45,221 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-31525MEDIUM4.3Missing Authorization vulnerability in WP Messiah WP Mobile Bottom Menu mobile-bottom-menu-for-wp allows Exploiting Inco...
CVE-2025-30853MEDIUM5.4Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images allows Exploitin...
CVE-2025-30844MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Watu Quiz watu...
CVE-2025-29049MEDIUM6.3Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker ...
CVE-2025-29036MEDIUM5.9An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component.
CVE-2025-26056MEDIUM5.4A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality....
CVE-2025-26055MEDIUM6.5An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tr...
CVE-2025-26054MEDIUM5.4Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuratio...
CVE-2025-29208MEDIUM6.5CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleter...
CVE-2025-28132MEDIUM4.6A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a ...
CVE-2025-28131MEDIUM4.6A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" ...
CVE-2025-25041MEDIUM5.5A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrit...
CVE-2025-21986MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: switchdev: Convert blocking notification chain...
CVE-2025-21984MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: mm: fix kernel BUG when userfaultfd_move encounters...
CVE-2025-21982MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: npcm8xx: Add NULL check in npcm8x...
CVE-2025-21981MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ice: fix memory leak in aRFS after reset Fix aRFS ...
CVE-2025-21980MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched: address a potential NULL pointer dereference...
CVE-2025-21978MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: Fix address space leak when Hyper-V DRM...
CVE-2025-21977MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fbdev: hyperv_fb: Fix hang in kdump kernel when on ...
CVE-2025-21976MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fbdev: hyperv_fb: Allow graceful removal of framebu...
CVE-2025-21975MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: handle errors in mlx5_chains_create_table...
CVE-2025-21974MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: return fail if interface is down in bnxt...
CVE-2025-21972MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: mctp: unshare packets when reassembling Ensur...
CVE-2025-21971MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net_sched: Prevent creation of classes with TC_H_RO...
CVE-2025-21970MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Bridge, fix the crash caused by LAG state...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now