2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54388MEDIUM4.6Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Conta...
CVE-2025-53008MEDIUM6.5GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide...
CVE-2025-52897MEDIUM6.1GLPI is a Free Asset and IT Management Software package. In versions 9.1.0 through 10.0.18, an unauthenticated user can ...
CVE-2025-52567MEDIUM5GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2025-8326CRITICAL9.8A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown ...
CVE-2025-47001MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-6348MEDIUM4.9The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in all ve...
CVE-2025-1394MEDIUM5.9The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Serv...
CVE-2025-1221MEDIUM5.9A Zigbee Radio Co-Processor (RCP), which is using SiLabs EmberZNet Zigbee stack, was unable to send messages to the host...
CVE-2025-38498MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: do_change_type(): refuse to operate on unmounted/no...
CVE-2025-8323HIGH8.8The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload ...
CVE-2025-8322HIGH8.8The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to ...
CVE-2025-8292HIGH8.8Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit...
CVE-2025-8321MEDIUM6.8Tesla Wall Connector Firmware Downgrade Vulnerability. This vulnerability allows physically present attackers to execute...
CVE-2025-8320HIGH8.8Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerabi...
CVE-2025-8217MEDIUM5.1The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the...
CVE-2025-4426MEDIUM6The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad...
CVE-2025-4425HIGH8.2The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad...
CVE-2025-4424MEDIUM6The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad...
CVE-2025-4423HIGH8.2The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad...
CVE-2025-4422HIGH8.2The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad...
CVE-2025-4421HIGH8.2The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad...
CVE-2025-25011HIGH7An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Pe...
CVE-2025-0712HIGH7An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Pe...
CVE-2025-8319MEDIUM6.1the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now