2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-37901MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: irqchip/qcom-mpm: Prevent crash when trying to hand...
CVE-2025-37900MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iommu: Fix two issues in iommu_copy_struct_from_use...
CVE-2025-37899HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The se...
CVE-2025-37898MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix module loading without patcha...
CVE-2025-37897MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: plfxlc: Remove erroneous assert in plfxlc_mac...
CVE-2025-37896MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: spi: spi-mem: Add fix to avoid divide error For so...
CVE-2025-37895MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix error handling path in bnxt_init_chip(...
CVE-2025-37894MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: use sock_gen_put() when sk_state is TCP_TIME_W...
CVE-2025-41228MEDIUM4.3VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. ...
CVE-2025-41227MEDIUM5.5VMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious...
CVE-2025-41226MEDIUM6.8VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor ...
CVE-2025-41225HIGH8.8The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to creat...
CVE-2025-26086HIGH7.5An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parame...
CVE-2025-4980MEDIUM6.9A vulnerability has been found in Netgear DGND3700 1.1.00.15_1.00.15NA and classified as problematic. This vulnerability...
CVE-2025-47941HIGH7.2TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS an...
CVE-2025-47940HIGH7.2TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4....
CVE-2025-47939MEDIUM5.4TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backe...
CVE-2025-47938LOW3.8TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51...
CVE-2025-47937MEDIUM5.3TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51...
CVE-2025-47936MEDIUM4.4TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS an...
CVE-2025-45862MEDIUM6.5TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in t...
CVE-2025-4978CRITICAL9.8A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects ...
CVE-2025-4977MEDIUM6.9A vulnerability, which was classified as problematic, has been found in Netgear DGND3700 1.1.00.15_1.00.15NA. Affected b...
CVE-2025-41231HIGH7.3VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Fo...
CVE-2025-41230HIGH7.5VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now