2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71311 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN r... |
| CVE-2025-71309 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix deadlock in ni_read_folio_cmpr Syzbo... |
| CVE-2025-71308 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix potential NULL pointer dereferen... |
| CVE-2025-71307 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NULL pointer dereference on pantho... |
| CVE-2025-71305 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/display/dp_mst: Add protection against 0 vcpi ... |
| CVE-2025-71304 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: smack: /smack/doi: accept previously used values W... |
| CVE-2025-71303 | MEDIUM | 4.7 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix race condition when checking rpm... |
| CVE-2025-0898 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and ... |
| CVE-2025-66593 | MEDIUM | 5.6 | 0.1% | May 27, 2026 | An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary ... |
| CVE-2025-66592 | MEDIUM | 5.6 | 0.1% | May 27, 2026 | An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local use... |
| CVE-2025-13593 | MEDIUM | 5.6 | 0.1% | May 27, 2026 | Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbi... |
| CVE-2025-13167 | MEDIUM | 5.4 | 0.3% | May 27, 2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functional... |
| CVE-2025-10466 | MEDIUM | 5.9 | 0.3% | May 27, 2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Syn... |
| CVE-2025-14481 | MEDIUM | 4.3 | 0.3% | May 27, 2026 | The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and includi... |
| CVE-2025-15649 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed... |
| CVE-2025-46307 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to acc... |
| CVE-2025-46280 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be ... |
| CVE-2025-43451 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be ... |
| CVE-2025-43290 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma ... |
| CVE-2025-43289 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macO... |
| CVE-2025-68709 | MEDIUM | 5.2 | 0.2% | May 26, 2026 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript exe... |
| CVE-2025-33221 | MEDIUM | 6 | 0.2% | May 26, 2026 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an i... |
| CVE-2025-36148 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transacti... |
| CVE-2025-36145 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could... |
| CVE-2025-14290 | MEDIUM | 5.4 | 0.2% | May 26, 2026 | IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now