2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38451 | MEDIUM | 5.5 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix GPF in bitmap_get_stats() The co... |
| CVE-2025-38450 | MEDIUM | 5.5 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: prevent NULL pointer dereferenc... |
| CVE-2025-38449 | MEDIUM | 5.5 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/gem: Acquire references on GEM handles for fram... |
| CVE-2025-38448 | MEDIUM | 4.7 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Fix race condition in TTY wa... |
| CVE-2025-38447 | HIGH | 7.1 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/rmap: fix potential out-of-bounds page table acc... |
| CVE-2025-38446 | HIGH | 7.1 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: clk: imx: Fix an out-of-bounds access in dispmix_cs... |
| CVE-2025-38445 | HIGH | 7.1 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix stack memory use after return in raid... |
| CVE-2025-38444 | MEDIUM | 5.5 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: raid10: cleanup memleak at raid10_make_request If ... |
| CVE-2025-38443 | HIGH | 7.8 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: nbd: fix uaf in nbd_genl_connect() error path Ther... |
| CVE-2025-38442 | MEDIUM | 5.5 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: block: reject bs > ps block devices when THP is dis... |
| CVE-2025-38441 | MEDIUM | 5.5 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: account for Ethernet header i... |
| CVE-2025-38440 | MEDIUM | 4.7 | 0.1% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix race between DIM disable and net_dim... |
| CVE-2025-38439 | MEDIUM | 5.5 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Set DMA unmap len correctly for XDP_REDIRE... |
| CVE-2025-38438 | MEDIUM | 5.5 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid ... |
| CVE-2025-38437 | HIGH | 7.8 | 0.2% | Jul 25, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potential use-after-free in oplock/lease... |
| CVE-2025-34139 | HIGH | 8.7 | 0.5% | Jul 25, 2025 | A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Mana... |
| CVE-2025-34138 | — | — | — | Jul 25, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority, as it is a duplicate of CVE-... |
| CVE-2025-34136 | MEDIUM | 6.9 | 0.5% | Jul 25, 2025 | An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Se... |
| CVE-2025-34114 | HIGH | 8.4 | 0.2% | Jul 25, 2025 | A client-side security misconfiguration vulnerability exists in OpenBlow whistleblowing platform across multiple version... |
| CVE-2025-2329 | MEDIUM | 5.3 | 0.2% | Jul 25, 2025 | In high traffic environments, a Silicon Labs OpenThread RCP (see impacted versions) fails to clear the SPI transmit buff... |
| CVE-2025-8160 | HIGH | 8.8 | 1.2% | Jul 25, 2025 | A vulnerability classified as critical has been found in Tenda AC20 up to 16.03.08.12. Affected is an unknown function o... |
| CVE-2025-8159 | CRITICAL | 9.8 | 14.3% | Jul 25, 2025 | A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. This issue affects the function formLang... |
| CVE-2025-52360 | HIGH | 8.8 | 0.5% | Jul 25, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search feature of Koha Library Management System v24.05. U... |
| CVE-2025-45467 | HIGH | 7.1 | 0.3% | Jul 25, 2025 | Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethe... |
| CVE-2025-44608 | MEDIUM | 6.5 | 0.3% | Jul 25, 2025 | CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now