2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38013 | HIGH | 7.8 | 0.2% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Set n_channels after allocating str... |
| CVE-2025-38012 | MEDIUM | 5.5 | 0.2% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: bpf_iter_scx_dsq_new() should always ini... |
| CVE-2025-38011 | MEDIUM | 5.5 | 0.2% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: csa unmap use uninterruptible lock Aft... |
| CVE-2025-38010 | MEDIUM | 5.5 | 0.2% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Use a bitmask for UTMI pad power ... |
| CVE-2025-38009 | MEDIUM | 5.5 | 0.2% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: disable napi on driver removal A warni... |
| CVE-2025-38008 | MEDIUM | 4.7 | 0.1% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted mem... |
| CVE-2025-38007 | MEDIUM | 5.5 | 0.2% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Add NULL check in uclogic_input_confi... |
| CVE-2025-38006 | MEDIUM | 5.5 | 0.2% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: mctp: Don't access ifa_index when missing In ... |
| CVE-2025-38005 | MEDIUM | 5.5 | 0.2% | Jun 18, 2025 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: k3-udma: Add missing locking Recent... |
| CVE-2025-23999 | MEDIUM | 4.3 | 0.2% | Jun 18, 2025 | Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-1088 | LOW | 2.7 | 0.4% | Jun 18, 2025 | In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to... |
| CVE-2025-5981 | MEDIUM | 6.5 | 0.2% | Jun 18, 2025 | Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIB... |
| CVE-2025-1562 | CRITICAL | 9.8 | 2.9% | Jun 18, 2025 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word... |
| CVE-2025-4955 | MEDIUM | 4.7 | 0.3% | Jun 18, 2025 | The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing the... |
| CVE-2025-51381 | CRITICAL | 9.8 | 0.6% | Jun 18, 2025 | An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an at... |
| CVE-2025-50202 | HIGH | 7.5 | 0.5% | Jun 18, 2025 | Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local fil... |
| CVE-2025-4413 | HIGH | 8.8 | 0.5% | Jun 18, 2025 | The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t... |
| CVE-2025-23252 | HIGH | 7.5 | 0.3% | Jun 18, 2025 | The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A succ... |
| CVE-2025-49149 | MEDIUM | 6.1 | 0.2% | Jun 17, 2025 | Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by ... |
| CVE-2025-49825 | CRITICAL | 9.8 | 7.8% | Jun 17, 2025 | Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions... |
| CVE-2025-49593 | MEDIUM | 6.8 | 0.3% | Jun 17, 2025 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t... |
| CVE-2025-49843 | LOW | 2.7 | 0.5% | Jun 17, 2025 | conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ... |
| CVE-2025-49824 | LOW | 1.7 | 0.2% | Jun 17, 2025 | conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ... |
| CVE-2025-49385 | HIGH | 7.1 | 0.1% | Jun 17, 2025 | Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou... |
| CVE-2025-49384 | HIGH | 7.1 | 0.1% | Jun 17, 2025 | Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now