2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21634 | MEDIUM | 5.5 | 0.1% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: remove kernfs active break A warnin... |
| CVE-2025-21632 | MEDIUM | 5.5 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Ensure shadow stack is active before "gett... |
| CVE-2025-0567 | MEDIUM | 4.5 | 0.2% | Jan 19, 2025 | A vulnerability classified as problematic was found in Epic Games Launcher up to 17.2.1. This vulnerability affects unkn... |
| CVE-2025-0560 | MEDIUM | 4.8 | 0.3% | Jan 18, 2025 | A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. Affected is... |
| CVE-2025-0559 | MEDIUM | 4.8 | 0.3% | Jan 18, 2025 | A vulnerability, which was classified as problematic, has been found in Campcodes School Management Software 1.0. This i... |
| CVE-2025-0557 | MEDIUM | 6.9 | 0.6% | Jan 18, 2025 | A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Ed... |
| CVE-2025-0515 | MEDIUM | 4.3 | 0.2% | Jan 18, 2025 | The Buzz Club – Night Club, DJ and Music Festival Event WordPress Theme theme for WordPress is vulnerable to unauthorize... |
| CVE-2025-0369 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all vers... |
| CVE-2025-0554 | MEDIUM | 4 | 0.3% | Jan 18, 2025 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value ... |
| CVE-2025-0318 | MEDIUM | 5.3 | 0.3% | Jan 18, 2025 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2025-23208 | MEDIUM | 5.3 | 0.4% | Jan 17, 2025 | zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (met... |
| CVE-2025-23205 | MEDIUM | 6.9 | 0.5% | Jan 17, 2025 | nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: 'self' grants any JupyterHub user th... |
| CVE-2025-23039 | MEDIUM | 5.2 | 0.2% | Jan 17, 2025 | Caido is a web security auditing toolkit. A Cross-Site Scripting (XSS) vulnerability was identified in Caido v0.45.0 due... |
| CVE-2025-0538 | MEDIUM | 4.8 | 0.4% | Jan 17, 2025 | A vulnerability, which was classified as problematic, was found in code-projects Tourism Management System 1.0. Affected... |
| CVE-2025-21185 | MEDIUM | 6.5 | 0.8% | Jan 17, 2025 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2025-0537 | MEDIUM | 4.8 | 0.3% | Jan 17, 2025 | A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. ... |
| CVE-2025-23201 | MEDIUM | 6.1 | 0.4% | Jan 16, 2025 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Script... |
| CVE-2025-23200 | MEDIUM | 5.4 | 30.9% | Jan 16, 2025 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t... |
| CVE-2025-23199 | MEDIUM | 5.4 | 1.2% | Jan 16, 2025 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t... |
| CVE-2025-23198 | MEDIUM | 5.4 | 0.3% | Jan 16, 2025 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t... |
| CVE-2025-23965 | MEDIUM | 6.5 | 0.2% | Jan 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kopatheme Kopa Nic... |
| CVE-2025-23963 | MEDIUM | 5.4 | 0.3% | Jan 16, 2025 | Missing Authorization vulnerability in flymke Mark Posts mark-posts allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-23962 | MEDIUM | 4.3 | 0.2% | Jan 16, 2025 | Missing Authorization vulnerability in jjtrabucco Goldstar goldstar allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-23961 | MEDIUM | 5.4 | 0.3% | Jan 16, 2025 | Missing Authorization vulnerability in wptasker WordPress Graphs & Charts graph-lite allows Exploiting Incorrectly Confi... |
| CVE-2025-23957 | MEDIUM | 4.3 | 0.3% | Jan 16, 2025 | Missing Authorization vulnerability in surdotly Sur.ly surly allows Exploiting Incorrectly Configured Access Control Sec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now