2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-21629MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP...
CVE-2025-0448MEDIUM4.3Inappropriate implementation in Compositing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform...
CVE-2025-0446MEDIUM4.3Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinc...
CVE-2025-0442MEDIUM6.5Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced...
CVE-2025-0441MEDIUM6.5Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtai...
CVE-2025-0440MEDIUM6.5Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker ...
CVE-2025-0439MEDIUM6.5Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in speci...
CVE-2025-0435MEDIUM6.5Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker ...
CVE-2025-0193MEDIUM5.2A stored Cross-site Scripting (XSS) vulnerability exists in the MGate 5121/5122/5123 Series firmware version v1.0 becaus...
CVE-2025-0354MEDIUM4.8Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earl...
CVE-2025-21101MEDIUM6.3Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability. A local malicious user could p...
CVE-2025-22997MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the prf_table_content component of Linksys E5600 Router Ver. 1.1.0....
CVE-2025-22996MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the spf_table_content component of Linksys E5600 Router Ver. 1.1.0....
CVE-2025-23019MEDIUM6.5IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.
CVE-2025-23018MEDIUM6.5IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a netw...
CVE-2025-23072MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-23041MEDIUM5.3Umbraco.Forms is a web form framework written for the nuget ecosystem. Character limits configured by editors for short ...
CVE-2025-23366MEDIUM4.8A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-...
CVE-2025-21403MEDIUM6.4On-Premises Data Gateway Information Disclosure Vulnerability
CVE-2025-21393MEDIUM6.3Microsoft SharePoint Server Spoofing Vulnerability
CVE-2025-21374MEDIUM5.5Windows CSC Service Information Disclosure Vulnerability
CVE-2025-21357MEDIUM6.7Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-21341MEDIUM6.6Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21340MEDIUM5.5Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
CVE-2025-21336MEDIUM5.6Windows Cryptographic Information Disclosure Vulnerability

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now