2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-71166MEDIUM5.4Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the admi...
CVE-2025-71165MEDIUM5.4Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the admi...
CVE-2025-71164MEDIUM5.4Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Edit...
CVE-2025-14557MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Face...
CVE-2025-14556MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag...
CVE-2025-11224MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and ...
CVE-2025-65397MEDIUM6.8An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 ...
CVE-2025-63644MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile...
CVE-2025-67835MEDIUM6.5Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notifi...
CVE-2025-67834MEDIUM5.4Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter.
CVE-2025-67833MEDIUM6.1Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter.
CVE-2025-65396MEDIUM6.1A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically prox...
CVE-2025-37185MEDIUM4.8Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2025-67399MEDIUM4.6An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive i...
CVE-2025-14242MEDIUM6.5A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls comman...
CVE-2025-71144MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mptcp: ensure context reset on disconnect() After ...
CVE-2025-71142MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cpuset: fix warning when disabling remote partition...
CVE-2025-71141MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/tilcdc: Fix removal actions in case of failed p...
CVE-2025-71139MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: kernel/kexec: fix IMA when allocation happens in CM...
CVE-2025-71138MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add missing NULL pointer check for pin...
CVE-2025-71135MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix possible null-pointer dereferences in...
CVE-2025-71134MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: change all pageblocks migrate type o...
CVE-2025-71132MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smc91x: fix broken irq-context in PREEMPT_RT When ...
CVE-2025-71131MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use req->iv after crypto_aea...
CVE-2025-71130MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Zero-initialize the eb.vma array in i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now