2025 CVE Vulnerabilities

45,225 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-2085MEDIUM6.1A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of ...
CVE-2025-2084MEDIUM6.1A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as p...
CVE-2025-1768MEDIUM6.5The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in a...
CVE-2025-21843MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/panthor: avoid garbage value in panthor_ioctl_d...
CVE-2025-21842MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: amdkfd: properly free gang_ctx_bo when failed to in...
CVE-2025-21841MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Fix cpufreq_policy ref counting...
CVE-2025-21840MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: thermal/netlink: Prevent userspace segmentation fau...
CVE-2025-21839MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before ent...
CVE-2025-21838MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: flush gadget workqueue after dev...
CVE-2025-21836MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IOR...
CVE-2025-21835MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor ...
CVE-2025-0959MEDIUM6.5The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_i...
CVE-2025-0863MEDIUM6.4The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' s...
CVE-2025-2061MEDIUM6.1A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. Th...
CVE-2025-26708MEDIUM4.2There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the Wi...
CVE-2025-0748MEDIUM4.3The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This ...
CVE-2025-1121MEDIUM6.8Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an ...
CVE-2025-2049MEDIUM5.1A vulnerability classified as problematic has been found in code-projects Blood Bank System 1.0. Affected is an unknown ...
CVE-2025-2047MEDIUM5.1A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This a...
CVE-2025-2042MEDIUM6.5A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects ...
CVE-2025-2040MEDIUM6.3A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is...
CVE-2025-27600MEDIUM6.5FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP ver...
CVE-2025-27506MEDIUM6.1NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vu...
CVE-2025-25294MEDIUM5.3Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway...
CVE-2025-25191MEDIUM5.4Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now