2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-71311MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN r...
CVE-2025-71309MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix deadlock in ni_read_folio_cmpr Syzbo...
CVE-2025-71308MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix potential NULL pointer dereferen...
CVE-2025-71307MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NULL pointer dereference on pantho...
CVE-2025-71305MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/display/dp_mst: Add protection against 0 vcpi ...
CVE-2025-71304MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smack: /smack/doi: accept previously used values W...
CVE-2025-71303MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix race condition when checking rpm...
CVE-2025-0898MEDIUM6.5The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and ...
CVE-2025-66593MEDIUM5.6An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary ...
CVE-2025-66592MEDIUM5.6An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local use...
CVE-2025-13593MEDIUM5.6Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbi...
CVE-2025-13167MEDIUM5.4Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functional...
CVE-2025-10466MEDIUM5.9Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Syn...
CVE-2025-14481MEDIUM4.3The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and includi...
CVE-2025-15649MEDIUM5.5IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed...
CVE-2025-46307MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to acc...
CVE-2025-46280MEDIUM5.5An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be ...
CVE-2025-43451MEDIUM5.5A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be ...
CVE-2025-43290MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma ...
CVE-2025-43289MEDIUM5.5A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macO...
CVE-2025-68709MEDIUM5.2SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript exe...
CVE-2025-33221MEDIUM6NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an i...
CVE-2025-36148MEDIUM6.1IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transacti...
CVE-2025-36145MEDIUM5.3IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could...
CVE-2025-14290MEDIUM5.4IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now