2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-40331HIGH7.8In the Linux kernel, the following vulnerability has been resolved: sctp: Prevent TOCTOU out-of-bounds write For the f...
CVE-2025-40328HIGH8.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_close_cached...
CVE-2025-2296HIGH8.4EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successf...
CVE-2025-14333HIGH8.1Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these b...
CVE-2025-14332HIGH7.3Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption a...
CVE-2025-14329HIGH8.8Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunde...
CVE-2025-14328HIGH8.8Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunde...
CVE-2025-14327HIGH7.5Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox E...
CVE-2025-14325HIGH7.3JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140...
CVE-2025-14323HIGH8.8Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.3...
CVE-2025-14322HIGH8Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed...
CVE-2025-14309HIGH7.5NULL Pointer Dereference vulnerability in ravynsoft ravynos.This issue affects ravynos: through 0.5.2.
CVE-2025-14307HIGH8.1An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The c...
CVE-2025-14286HIGH7.5A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionalit...
CVE-2025-13662HIGH7.8Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to ...
CVE-2025-13661HIGH8Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write ...
CVE-2025-13659HIGH8.8Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a...
CVE-2025-13604HIGH7.2The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2025-13428HIGH7.2A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an ...
CVE-2025-13071HIGH7.1The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back ...
CVE-2025-12807HIGH8.7A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive data...
CVE-2025-12705HIGH7.2The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several param...
CVE-2025-12381HIGH7.8Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, P...
CVE-2025-10655HIGH8.8SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled para...
CVE-2025-66204HIGH8.1WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now