2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31525 | MEDIUM | 4.3 | 0.3% | Apr 1, 2025 | Missing Authorization vulnerability in WP Messiah WP Mobile Bottom Menu mobile-bottom-menu-for-wp allows Exploiting Inco... |
| CVE-2025-30853 | MEDIUM | 5.4 | 0.4% | Apr 1, 2025 | Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images allows Exploitin... |
| CVE-2025-30844 | MEDIUM | 6.1 | 0.3% | Apr 1, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Watu Quiz watu... |
| CVE-2025-29049 | MEDIUM | 6.3 | 0.5% | Apr 1, 2025 | Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker ... |
| CVE-2025-29036 | MEDIUM | 5.9 | 0.3% | Apr 1, 2025 | An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the user.js component. |
| CVE-2025-26056 | MEDIUM | 5.4 | 1.0% | Apr 1, 2025 | A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality.... |
| CVE-2025-26055 | MEDIUM | 6.5 | 1.1% | Apr 1, 2025 | An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tr... |
| CVE-2025-26054 | MEDIUM | 5.4 | 0.3% | Apr 1, 2025 | Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuratio... |
| CVE-2025-29208 | MEDIUM | 6.5 | 0.3% | Apr 1, 2025 | CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleter... |
| CVE-2025-28132 | MEDIUM | 4.6 | 0.3% | Apr 1, 2025 | A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a ... |
| CVE-2025-28131 | MEDIUM | 4.6 | 0.4% | Apr 1, 2025 | A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" ... |
| CVE-2025-25041 | MEDIUM | 5.5 | 0.1% | Apr 1, 2025 | A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrit... |
| CVE-2025-21986 | MEDIUM | 5.5 | 0.1% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: switchdev: Convert blocking notification chain... |
| CVE-2025-21984 | MEDIUM | 4.7 | 0.1% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm: fix kernel BUG when userfaultfd_move encounters... |
| CVE-2025-21982 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: npcm8xx: Add NULL check in npcm8x... |
| CVE-2025-21981 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: ice: fix memory leak in aRFS after reset Fix aRFS ... |
| CVE-2025-21980 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched: address a potential NULL pointer dereference... |
| CVE-2025-21978 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: Fix address space leak when Hyper-V DRM... |
| CVE-2025-21977 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: fbdev: hyperv_fb: Fix hang in kdump kernel when on ... |
| CVE-2025-21976 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: fbdev: hyperv_fb: Allow graceful removal of framebu... |
| CVE-2025-21975 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: handle errors in mlx5_chains_create_table... |
| CVE-2025-21974 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: return fail if interface is down in bnxt... |
| CVE-2025-21972 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: mctp: unshare packets when reassembling Ensur... |
| CVE-2025-21971 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net_sched: Prevent creation of classes with TC_H_RO... |
| CVE-2025-21970 | MEDIUM | 5.5 | 0.2% | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Bridge, fix the crash caused by LAG state... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now