2025 CVE Vulnerabilities

45,267 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-38013HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Set n_channels after allocating str...
CVE-2025-38012MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched_ext: bpf_iter_scx_dsq_new() should always ini...
CVE-2025-38011MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: csa unmap use uninterruptible lock Aft...
CVE-2025-38010MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Use a bitmask for UTMI pad power ...
CVE-2025-38009MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: disable napi on driver removal A warni...
CVE-2025-38008MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted mem...
CVE-2025-38007MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Add NULL check in uclogic_input_confi...
CVE-2025-38006MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: mctp: Don't access ifa_index when missing In ...
CVE-2025-38005MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma: Add missing locking Recent...
CVE-2025-23999MEDIUM4.3Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S...
CVE-2025-1088LOW2.7In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to...
CVE-2025-5981MEDIUM6.5Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIB...
CVE-2025-1562CRITICAL9.8The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word...
CVE-2025-4955MEDIUM4.7The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing the...
CVE-2025-51381CRITICAL9.8An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an at...
CVE-2025-50202HIGH7.5Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local fil...
CVE-2025-4413HIGH8.8The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t...
CVE-2025-23252HIGH7.5The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A succ...
CVE-2025-49149MEDIUM6.1Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by ...
CVE-2025-49825CRITICAL9.8Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions...
CVE-2025-49593MEDIUM6.8Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2025-49843LOW2.7conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ...
CVE-2025-49824LOW1.7conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ...
CVE-2025-49385HIGH7.1Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou...
CVE-2025-49384HIGH7.1Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now