2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-14042MEDIUM6.4The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-48977MEDIUM6.5Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the ...
CVE-2025-67903MEDIUM5.3Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
CVE-2025-70116MEDIUM4.3A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can r...
CVE-2025-68712MEDIUM5.5SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerp...
CVE-2025-71312MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_...
CVE-2025-71311MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN r...
CVE-2025-71309MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix deadlock in ni_read_folio_cmpr Syzbo...
CVE-2025-71308MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix potential NULL pointer dereferen...
CVE-2025-71307MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NULL pointer dereference on pantho...
CVE-2025-71305MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/display/dp_mst: Add protection against 0 vcpi ...
CVE-2025-71304MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smack: /smack/doi: accept previously used values W...
CVE-2025-71303MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix race condition when checking rpm...
CVE-2025-0898MEDIUM6.5The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and ...
CVE-2025-66593MEDIUM5.6An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary ...
CVE-2025-66592MEDIUM5.6An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local use...
CVE-2025-13593MEDIUM5.6Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbi...
CVE-2025-13167MEDIUM5.4Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functional...
CVE-2025-10466MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Syn...
CVE-2025-14481MEDIUM4.3The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and includi...
CVE-2025-15649MEDIUM5.5IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed...
CVE-2025-46307MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to acc...
CVE-2025-46280MEDIUM5.5An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be ...
CVE-2025-43451MEDIUM5.5A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be ...
CVE-2025-43290MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now