2025 CVE Vulnerabilities

45,227 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-1743MEDIUM6.9A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of t...
CVE-2025-27157MEDIUM5.3Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and ...
CVE-2025-25329MEDIUM5.5An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sens...
CVE-2025-1742MEDIUM6.1A vulnerability, which was classified as problematic, has been found in pihome-shc PiHome 2.0. Affected by this issue is...
CVE-2025-25334MEDIUM5.5An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via sup...
CVE-2025-25331MEDIUM5.5An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying...
CVE-2025-25330MEDIUM5.5An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supply...
CVE-2025-25326MEDIUM5.5An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to acce...
CVE-2025-25325MEDIUM5.5An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive u...
CVE-2025-25324MEDIUM5.5An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user informati...
CVE-2025-25323MEDIUM5.5An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sens...
CVE-2025-1741MEDIUM5.1A vulnerability classified as problematic was found in b1gMail up to 7.4.1-pl1. Affected by this vulnerability is an unk...
CVE-2025-1738MEDIUM6.2A Password Transmitted over Query String vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionS...
CVE-2025-1693MEDIUM6.8The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database clu...
CVE-2025-1691MEDIUM6.5The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autoco...
CVE-2025-1450MEDIUM5.4The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp –...
CVE-2025-1690MEDIUM5.4The ThemeMakers Stripe Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stripe' short...
CVE-2025-1689MEDIUM5.4The ThemeMakers PayPal Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypa...
CVE-2025-1686MEDIUM4.9Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Nam...
CVE-2025-0469MEDIUM5.4The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2025-21795MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: NFSD: fix hang in nfsd4_shutdown_callback If nfs4_...
CVE-2025-21793MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: sn-f-ospi: Fix division by zero When there is...
CVE-2025-21792MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ax25: Fix refcount leak caused by setting SO_BINDTO...
CVE-2025-21790MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vxlan: check vxlan_vnigroup_init() return value vx...
CVE-2025-21788MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw: fix memleak in certai...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now