2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-21634MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: remove kernfs active break A warnin...
CVE-2025-21632MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Ensure shadow stack is active before "gett...
CVE-2025-0567MEDIUM4.5A vulnerability classified as problematic was found in Epic Games Launcher up to 17.2.1. This vulnerability affects unkn...
CVE-2025-0560MEDIUM4.8A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. Affected is...
CVE-2025-0559MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This i...
CVE-2025-0557MEDIUM6.9A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Ed...
CVE-2025-0515MEDIUM4.3The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthorize...
CVE-2025-0369MEDIUM6.4The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all vers...
CVE-2025-0554MEDIUM4The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value ...
CVE-2025-0318MEDIUM5.3The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2025-23208MEDIUM5.3zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (met...
CVE-2025-23205MEDIUM6.9nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: 'self' grants any JupyterHub user th...
CVE-2025-23039MEDIUM5.2Caido is a web security auditing toolkit. A Cross-Site Scripting (XSS) vulnerability was identified in Caido v0.45.0 due...
CVE-2025-0538MEDIUM4.8A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected...
CVE-2025-21185MEDIUM6.5Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2025-0537MEDIUM4.8A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. ...
CVE-2025-23201MEDIUM6.1librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Script...
CVE-2025-23200MEDIUM5.4librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t...
CVE-2025-23199MEDIUM5.4librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t...
CVE-2025-23198MEDIUM5.4librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t...
CVE-2025-23965MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kopatheme Kopa Nic...
CVE-2025-23963MEDIUM5.4Missing Authorization vulnerability in flymke Mark Posts mark-posts allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-23962MEDIUM4.3Missing Authorization vulnerability in jjtrabucco Goldstar goldstar allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-23961MEDIUM5.4Missing Authorization vulnerability in wptasker WordPress Graphs & Charts graph-lite allows Exploiting Incorrectly Confi...
CVE-2025-23957MEDIUM4.3Missing Authorization vulnerability in surdotly Sur.ly surly allows Exploiting Incorrectly Configured Access Control Sec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now