2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-25082MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Chirkov FlexID...
CVE-2025-25081MEDIUM4.2Missing Authorization vulnerability in DeannaS Embed RSS embed-rss allows Exploiting Incorrectly Configured Access Contr...
CVE-2025-25080MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gubbigubbi Kona Ga...
CVE-2025-25079MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Garrett Grimm Simp...
CVE-2025-25078MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrew Norcross Go...
CVE-2025-25077MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dugbug Easy Chart ...
CVE-2025-25076MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Gra...
CVE-2025-25073MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyl...
CVE-2025-0302MEDIUM5.5in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.
CVE-2025-23085MEDIUM5.3A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additiona...
CVE-2025-1072MEDIUM6.5A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to...
CVE-2025-22402MEDIUM5.4Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML...
CVE-2025-1086MEDIUM6.9A vulnerability has been found in Safetytest Cloud-Master Server up to 1.1.1 and classified as critical. This vulnerabil...
CVE-2025-1085MEDIUM5.3A vulnerability, which was classified as problematic, was found in Animati PACS up to 1.24.12.09.03. This affects an unk...
CVE-2025-1084MEDIUM5.3A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by ...
CVE-2025-21404MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2025-21267MEDIUM4.4Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2025-21253MEDIUM5.3Microsoft Edge for IOS and Android Spoofing Vulnerability
CVE-2025-1083MEDIUM6.8A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerabilit...
CVE-2025-1082MEDIUM5.4A vulnerability classified as problematic has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected is an unknown f...
CVE-2025-1004MEDIUM5.3Certain HP LaserJet Pro printers may potentially experience a denial of service when a user sends a raw JPEG file to the...
CVE-2025-0158MEDIUM5.5IBM EntireX 11.1 could allow a local user to cause a denial of service due to an unhandled error and fault isolation.
CVE-2025-22936MEDIUM5.7An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote atta...
CVE-2025-22866MEDIUM4Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number o...
CVE-2025-1078MEDIUM5.3A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now