2025 CVE Vulnerabilities
45,225 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2085 | MEDIUM | 6.1 | 0.3% | Mar 7, 2025 | A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of ... |
| CVE-2025-2084 | MEDIUM | 6.1 | 0.3% | Mar 7, 2025 | A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as p... |
| CVE-2025-1768 | MEDIUM | 6.5 | 0.5% | Mar 7, 2025 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in a... |
| CVE-2025-21843 | MEDIUM | 5.5 | 0.2% | Mar 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: avoid garbage value in panthor_ioctl_d... |
| CVE-2025-21842 | MEDIUM | 5.5 | 0.2% | Mar 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: amdkfd: properly free gang_ctx_bo when failed to in... |
| CVE-2025-21841 | MEDIUM | 5.5 | 0.2% | Mar 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Fix cpufreq_policy ref counting... |
| CVE-2025-21840 | MEDIUM | 5.5 | 0.2% | Mar 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: thermal/netlink: Prevent userspace segmentation fau... |
| CVE-2025-21839 | MEDIUM | 5.5 | 0.2% | Mar 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Load DR6 with guest value only before ent... |
| CVE-2025-21838 | MEDIUM | 5.5 | 0.2% | Mar 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: flush gadget workqueue after dev... |
| CVE-2025-21836 | MEDIUM | 5.5 | 0.2% | Mar 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IOR... |
| CVE-2025-21835 | MEDIUM | 5.5 | 0.2% | Mar 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: fix MIDI Streaming descriptor ... |
| CVE-2025-0959 | MEDIUM | 6.5 | 0.4% | Mar 7, 2025 | The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_i... |
| CVE-2025-0863 | MEDIUM | 6.4 | 0.3% | Mar 7, 2025 | The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'idx_frame' s... |
| CVE-2025-2061 | MEDIUM | 6.1 | 0.5% | Mar 7, 2025 | A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. Th... |
| CVE-2025-26708 | MEDIUM | 4.2 | 0.1% | Mar 7, 2025 | There is a configuration defect vulnerability in ZTELink 5.4.9 for iOS. This vulnerability is caused by a flaw in the Wi... |
| CVE-2025-0748 | MEDIUM | 4.3 | 0.2% | Mar 7, 2025 | The Homey theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.3. This ... |
| CVE-2025-1121 | MEDIUM | 6.8 | 0.1% | Mar 7, 2025 | Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an ... |
| CVE-2025-2049 | MEDIUM | 5.1 | 0.4% | Mar 6, 2025 | A vulnerability classified as problematic has been found in code-projects Blood Bank System 1.0. Affected is an unknown ... |
| CVE-2025-2047 | MEDIUM | 5.1 | 0.3% | Mar 6, 2025 | A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This a... |
| CVE-2025-2042 | MEDIUM | 6.5 | 0.2% | Mar 6, 2025 | A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects ... |
| CVE-2025-2040 | MEDIUM | 6.3 | 0.4% | Mar 6, 2025 | A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is... |
| CVE-2025-27600 | MEDIUM | 6.5 | 0.3% | Mar 6, 2025 | FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP ver... |
| CVE-2025-27506 | MEDIUM | 6.1 | 0.7% | Mar 6, 2025 | NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vu... |
| CVE-2025-25294 | MEDIUM | 5.3 | 0.3% | Mar 6, 2025 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway... |
| CVE-2025-25191 | MEDIUM | 5.4 | 0.3% | Mar 6, 2025 | Group-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now