2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-22763MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Brizy Pro...
CVE-2025-22732MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Admiral Ad Blockin...
CVE-2025-22727MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps MailChim...
CVE-2025-22718MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Event ...
CVE-2025-22262MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WittyFolk Bonjour ...
CVE-2025-21664MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dm thin: make get_first_thin use rcu-safe list firs...
CVE-2025-21663MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from...
CVE-2025-21662MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when fun...
CVE-2025-21661MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix missing lookup table cleanups ...
CVE-2025-21660MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix unexpectedly changed path in ksmbd_vfs_k...
CVE-2025-21659MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netdev: prevent accessing NAPI instances from anoth...
CVE-2025-21658MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid NULL pointer dereference if no valid e...
CVE-2025-21657MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched_ext: Replace rq_lock() to raw_spin_rq_lock() ...
CVE-2025-21656MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hwmon: (drivetemp) Fix driver producing garbage dat...
CVE-2025-0615MEDIUM5.3Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability allows an attacker to modify an email ...
CVE-2025-0614MEDIUM5.3Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a si...
CVE-2025-0450MEDIUM5.4The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality i...
CVE-2025-0371MEDIUM5.4The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up...
CVE-2025-23086MEDIUM6.1On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-pro...
CVE-2025-24014MEDIUM5.5Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mod...
CVE-2025-23214MEDIUM6.9Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ...
CVE-2025-23221MEDIUM5.4Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. This vulne...
CVE-2025-24013MEDIUM5.3CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name ...
CVE-2025-24010MEDIUM6.5Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development s...
CVE-2025-22620MEDIUM5gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions whe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now