2025 CVE Vulnerabilities

45,262 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-7070HIGH8.8A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulner...
CVE-2025-53366HIGH8.7The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi...
CVE-2025-53365HIGH8.7The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi...
CVE-2025-7069MEDIUM5.5A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link...
CVE-2025-7068MEDIUM5.5A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5F...
CVE-2025-53602MEDIUM5.3Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-...
CVE-2025-7067MEDIUM5.5A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_...
CVE-2025-53485HIGH7.5SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user...
CVE-2025-53484CRITICAL9.8User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPag...
CVE-2025-53483HIGH8.8ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF toke...
CVE-2025-53482MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53481HIGH7.5Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Al...
CVE-2025-52497MEDIUM4.8Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls...
CVE-2025-52496HIGH7.8Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may b...
CVE-2025-49601MEDIUM6.5In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes be...
CVE-2025-49600MEDIUM4.9In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal e...
CVE-2025-46733HIGH7.9OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2025-38234MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======...
CVE-2025-38233HIGH7.8In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix clobbered r15 during livepatc...
CVE-2025-38232MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and export...
CVE-2025-38231MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfsd: Initialize ssc before laundromat_work to prev...
CVE-2025-38230HIGH7.8In the Linux kernel, the following vulnerability has been resolved: jfs: validate AG parameters in dbMount() to prevent...
CVE-2025-38229MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: cxusb: no longer judge rbuf when the write f...
CVE-2025-38228MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: imagination: fix a potential memory leak in ...
CVE-2025-38227HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now