2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22763 | MEDIUM | 6.1 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Brizy Pro... |
| CVE-2025-22732 | MEDIUM | 6.5 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Admiral Ad Blockin... |
| CVE-2025-22727 | MEDIUM | 6.5 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps MailChim... |
| CVE-2025-22718 | MEDIUM | 6.5 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Event ... |
| CVE-2025-22262 | MEDIUM | 5.9 | 0.2% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WittyFolk Bonjour ... |
| CVE-2025-21664 | MEDIUM | 5.5 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: dm thin: make get_first_thin use rcu-safe list firs... |
| CVE-2025-21663 | MEDIUM | 5.5 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from... |
| CVE-2025-21662 | MEDIUM | 5.5 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when fun... |
| CVE-2025-21661 | MEDIUM | 5.5 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix missing lookup table cleanups ... |
| CVE-2025-21660 | MEDIUM | 5.5 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix unexpectedly changed path in ksmbd_vfs_k... |
| CVE-2025-21659 | MEDIUM | 5.5 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: netdev: prevent accessing NAPI instances from anoth... |
| CVE-2025-21658 | MEDIUM | 5.5 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid NULL pointer dereference if no valid e... |
| CVE-2025-21657 | MEDIUM | 5.5 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Replace rq_lock() to raw_spin_rq_lock() ... |
| CVE-2025-21656 | MEDIUM | 5.5 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (drivetemp) Fix driver producing garbage dat... |
| CVE-2025-0615 | MEDIUM | 5.3 | 0.4% | Jan 21, 2025 | Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability allows an attacker to modify an email ... |
| CVE-2025-0614 | MEDIUM | 5.3 | 0.4% | Jan 21, 2025 | Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a si... |
| CVE-2025-0450 | MEDIUM | 5.4 | 0.2% | Jan 21, 2025 | The Betheme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom JS functionality i... |
| CVE-2025-0371 | MEDIUM | 5.4 | 0.3% | Jan 21, 2025 | The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up... |
| CVE-2025-23086 | MEDIUM | 6.1 | 0.4% | Jan 21, 2025 | On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-pro... |
| CVE-2025-24014 | MEDIUM | 5.5 | 0.3% | Jan 20, 2025 | Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mod... |
| CVE-2025-23214 | MEDIUM | 6.9 | 0.6% | Jan 20, 2025 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ... |
| CVE-2025-23221 | MEDIUM | 5.4 | 0.6% | Jan 20, 2025 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. This vulne... |
| CVE-2025-24013 | MEDIUM | 5.3 | 0.5% | Jan 20, 2025 | CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name ... |
| CVE-2025-24010 | MEDIUM | 6.5 | 0.3% | Jan 20, 2025 | Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development s... |
| CVE-2025-22620 | MEDIUM | 5 | 0.4% | Jan 20, 2025 | gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions whe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now